CVE-2023-6942: Mitsubishielectric Ezsocket
High severity, CVSS 7.5. EPSS: 0.9% chance of exploitation in the next 30 days.
Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 to 5.92, GT Designer3 Version1(GOT1000) versions 1.325P and prior, GT Designer3 Version1(GOT2000) versions 1.320J and prior, GX Works2 versions 1.11M to 1.626C, GX Works3 versions 1.106L and prior, MELSOFT Navigator versions 1.04E to 2.102G, MT Works2 versions 1.190Y and prior, MX Component versions 4.00A to 5.007H and MX OPC Server DA/UA all versions allows a remote unauthenticated attacker to bypass authentication by sending specially crafted packets and connect to the products illegally.
Affected products
- Mitsubishielectric Ezsocket: from 3.0
- Mitsubishielectric Fr CONFIGURATOR2: any version
- Mitsubishielectric GOT1000: any version
- Mitsubishielectric GOT2000: any version
- Mitsubishielectric Gx WORKS2: from 1.11m
- Mitsubishielectric Gx WORKS3: any version
- Mitsubishielectric Mc WORKS64: any version
- Mitsubishielectric Melsoft Navigator: from 1.04e
- Mitsubishielectric Mt WORKS2: any version
- Mitsubishielectric Mx Component: from 4.00a
Published 2024-01-30. Last modified 2026-06-17.