CVE-2023-5247
Description
Malicious Code Execution Vulnerability due to External Control of File Name or Path in multiple Mitsubishi Electric FA Engineering Software Products allows a malicious attacker to execute a malicious code by having legitimate users open a specially crafted project file, which could result in information disclosure, tampering and deletion, or a denial-of-service (DoS) condition.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Multiple Mitsubishi Electric FA engineering products allow code execution via a crafted project file, leading to info disclosure, tampering, deletion, or DoS.
Vulnerability
CVE-2023-5247 is an external control of file name or path (CWE-73) vulnerability in multiple Mitsubishi Electric FA Engineering Software Products. The affected products include GX Works3 (all versions), MELSOFT iQ AppPortal (all versions), MELSOFT Navigator (all versions), and Motion Control Setting (all versions, bundled with GX Works3) [1]. The vulnerability occurs when a legitimate user opens a specially crafted project file, allowing an attacker to control file names or paths during project processing [1].
Exploitation
An attacker must craft a malicious project file and convince a legitimate user to open it using an affected product [1]. The attacker does not require any special network position or authentication; user interaction is the primary attack vector. The exploitation does not involve a race condition or other timing-dependent steps [1].
Impact
Successful exploitation enables the attacker to execute malicious code within the context of the affected software [1]. This can result in information disclosure (theft of data), tampering and deletion of files, or a denial-of-service (DoS) condition [1]. The attacker gains the ability to perform arbitrary operations on the victim's system, limited by the privileges of the user running the FA engineering software [1].
Mitigation
Mitsubishi Electric recommends workarounds as no patch is announced for all versions [1]. These include installing antivirus software on the PC using the affected products, using the products only on trusted networks and blocking remote login from untrusted hosts/users, and using firewalls or VPNs to prevent unauthorized access when connecting to the internet [1]. Affected users should also restrict remote login to trusted users only [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
4- Range: all versions
- Mitsubishi Electric Corporation/MELSOFT iQ AppPortalv5Range: all versions
- Range: all versions
- Range: all versions
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-016_en.pdfmitrevendor-advisory
- jvn.jp/vu/JVNVU93383160/mitregovernment-resource
News mentions
0No linked articles in our index yet.