CVE-2022-29831
Description
Use of Hard-coded Password vulnerability in Mitsubishi Electric Corporation GX Works3 versions from 1.015R to 1.095Z allows a remote unauthenticated attacker to obtain information about the project file for MELSEC safety CPU modules.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A hard-coded password in Mitsubishi GX Works3 (1.015R to 1.095Z) lets an unauthenticated remote attacker extract project file information for MELSEC safety CPUs.
Vulnerability
CVE-2022-29831 is a use of hard-coded password vulnerability in Mitsubishi Electric GX Works3 versions 1.015R to 1.095Z [1][2]. The product stores credentials in plaintext or embeds a password that is not changeable, allowing an attacker who knows the hard-coded value to authenticate without authorization. This issue specifically affects the handling of project files for MELSEC safety CPU modules.
Exploitation
A remote unauthenticated attacker with network access to a system running an affected version of GX Works3 can exploit this flaw without any user interaction or special privileges [1]. By leveraging the publicly known or discoverable hard-coded password, the attacker can connect to the engineering software's communication interface and query project data.
Impact
Successful exploitation enables the attacker to obtain information about the project file for MELSEC safety CPU modules [1][2]. This disclosure of sensitive configuration data could aid in further attacks against the industrial control system. The compromise is limited to information disclosure; the attacker does not gain code execution or control of the CPU module itself.
Mitigation
Mitsubishi Electric has released GX Works3 version 1.096A and later which are not affected by this specific vulnerability [1]. Users should update to 1.096A or newer. If updating is not immediately possible, refer to vendor guidance for limiting network exposure and using firewall rules to block unauthorized access to the engineering station. No KEV listing or public workaround was provided in the available references.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: >=1.015R, <=1.095Z
- Range: from 1.015R to 1.095Z
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-015_en.pdfmitrevendor-advisory
- jvn.jp/vu/JVNVU97244961mitregovernment-resource
- www.cisa.gov/uscert/ics/advisories/icsa-22-333-05mitregovernment-resource
News mentions
0No linked articles in our index yet.