VYPR
Unrated severityNVD Advisory· Published Nov 24, 2022· Updated Apr 25, 2025

CVE-2022-29827

CVE-2022-29827

Description

Use of Hard-coded Cryptographic Key vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A and later allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated attackers may view programs and project files or execute programs illegally.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Hard-coded cryptographic key in Mitsubishi GX Works3 lets remote unauthenticated attackers disclose sensitive data like programs and project files.

Vulnerability

CVE-2022-29827 is a use of hard-coded cryptographic key vulnerability in Mitsubishi Electric GX Works3. Affected versions are 1.000A through 1.011M, 1.015R through 1.087R, 1.090U, 1.095Z, and 1.096A and later [1][2]. The vulnerability allows a remote unauthenticated attacker to disclose sensitive information due to the static key used for cryptographic operations.

Exploitation

An attacker does not require authentication or any special network position; they only need network access to the affected system [1]. The hard-coded key can be extracted or used directly to decrypt or access protected data, enabling the attacker to view program files and project files without any user interaction or privileges.

Impact

Successful exploitation allows an unauthenticated attacker to view programs and project files, and potentially execute programs illegally [1][2]. This compromises the confidentiality of sensitive engineering data and could lead to unauthorized control over MELSEC iQ-R/F/L series CPU modules and OPC UA server modules, depending on the version and configuration [1].

Mitigation

Mitsubishi Electric has released updates; users should upgrade GX Works3 to a version that addresses the vulnerability. Refer to the vendor advisory and the affected versions list for the exact fixed version [1][2]. For a complete list of affected products and specific fixes, consult the CISA advisory and Japanese JVN page. If upgrading is not possible, restrict network access to the software and implement network segmentation as a workaround.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.