CVE-2023-5247: Mitsubishielectric Gx WORKS3
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Malicious Code Execution Vulnerability due to External Control of File Name or Path in multiple Mitsubishi Electric FA Engineering Software Products allows a malicious attacker to execute a malicious code by having legitimate users open a specially crafted project file, which could result in information disclosure, tampering and deletion, or a denial-of-service (DoS) condition.
Affected products
- Mitsubishielectric Gx WORKS3: any version
- Mitsubishielectric Melsoft Iq Appportal: any version
- Mitsubishielectric Melsoft Navigator: any version
- Mitsubishielectric Motion Control Setting: any version
Published 2023-11-30. Last modified 2026-06-17.