VYPR
Unrated severityNVD Advisory· Published Nov 30, 2023· Updated Dec 2, 2024

CVE-2023-5247

CVE-2023-5247

Description

Malicious Code Execution Vulnerability due to External Control of File Name or Path in multiple Mitsubishi Electric FA Engineering Software Products allows a malicious attacker to execute a malicious code by having legitimate users open a specially crafted project file, which could result in information disclosure, tampering and deletion, or a denial-of-service (DoS) condition.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Multiple Mitsubishi Electric FA engineering products allow code execution via a crafted project file, leading to info disclosure, tampering, deletion, or DoS.

Vulnerability

CVE-2023-5247 is an external control of file name or path (CWE-73) vulnerability in multiple Mitsubishi Electric FA Engineering Software Products. The affected products include GX Works3 (all versions), MELSOFT iQ AppPortal (all versions), MELSOFT Navigator (all versions), and Motion Control Setting (all versions, bundled with GX Works3) [1]. The vulnerability occurs when a legitimate user opens a specially crafted project file, allowing an attacker to control file names or paths during project processing [1].

Exploitation

An attacker must craft a malicious project file and convince a legitimate user to open it using an affected product [1]. The attacker does not require any special network position or authentication; user interaction is the primary attack vector. The exploitation does not involve a race condition or other timing-dependent steps [1].

Impact

Successful exploitation enables the attacker to execute malicious code within the context of the affected software [1]. This can result in information disclosure (theft of data), tampering and deletion of files, or a denial-of-service (DoS) condition [1]. The attacker gains the ability to perform arbitrary operations on the victim's system, limited by the privileges of the user running the FA engineering software [1].

Mitigation

Mitsubishi Electric recommends workarounds as no patch is announced for all versions [1]. These include installing antivirus software on the PC using the affected products, using the products only on trusted networks and blocking remote login from untrusted hosts/users, and using firewalls or VPNs to prevent unauthorized access when connecting to the internet [1]. Affected users should also restrict remote login to trusted users only [1].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

4

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.