CVE-2023-6943
Description
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 to 5.92, GT Designer3 Version1(GOT1000) versions 1.325P and prior, GT Designer3 Version1(GOT2000) versions 1.320J and prior, GX Works2 versions 1.11M to 1.626C, GX Works3 versions 1.106L and prior, MELSOFT Navigator versions 1.04E to 2.102G, MT Works2 versions 1.190Y and prior, MX Component versions 4.00A to 5.007H and MX OPC Server DA/UA all versions allows a remote unauthenticated attacker to execute a malicious code by RPC with a path to a malicious library while connected to the products.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An unsafe reflection vulnerability in multiple Mitsubishi Electric FA engineering software products allows remote unauthenticated attackers to execute malicious code via RPC.
Vulnerability
An unsafe reflection vulnerability (CWE-470) exists in several Mitsubishi Electric FA engineering software products. The affected products and versions are: EZSocket versions 3.0 to 5.92, GT Designer3 Version1(GOT1000) versions 1.325P and prior, GT Designer3 Version1(GOT2000) versions 1.320J and prior, GX Works2 versions 1.11M to 1.626C, GX Works3 versions 1.106L and prior, MELSOFT Navigator versions 1.04E to 2.102G, MT Works2 versions 1.190Y and prior, MX Component versions 4.00A to 5.007H, and MX OPC Server DA/UA (software packaged with MC Works64) all versions [1][2]. The vulnerability allows externally-controlled input to select classes or code, enabling unsafe reflection.
Exploitation
To exploit this vulnerability, an attacker must be connected to the affected product remotely. While connected, the attacker can call a function with a path to a malicious library via RPC [1][2]. No authentication is required for this step, and the attack is remotely exploitable with low complexity [2]. The attacker sends a crafted request that includes a reference to a malicious library, and the product then loads and executes the attacker-supplied code.
Impact
Successful exploitation allows the attacker to execute arbitrary malicious code on the affected product [1][2]. This can lead to disclosure, tampering, destruction, or deletion of information, as well as causing a denial-of-service (DoS) condition on the products [1][2]. The attacker gains the ability to perform these actions without any prior authorization.
Mitigation
Mitsubishi Electric has released updated versions for some of the affected products. Users should refer to the vendor's information for the specific fixed version for each product [1]. For MX OPC Server DA/UA, no patch is currently available; users are advised to apply workarounds as recommended by the vendor [1][2]. Users should also consider network segmentation and access controls to limit exposure to untrusted networks.
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
173.0 to 5.92+ 1 more
- (no CPE)range: 3.0 to 5.92
- (no CPE)range: 3.0 to 5.92
- Range: <=1.106L
1.04E to 2.102G+ 1 more
- (no CPE)range: 1.04E to 2.102G
- (no CPE)range: 1.04E to 2.102G
(expand)+ 1 more
- (no CPE)
- (no CPE)range: all versions
<=1.190Y+ 1 more
- (no CPE)range: <=1.190Y
- (no CPE)range: 1.190Y and prior
<=1.325P+ 2 more
- (no CPE)range: <=1.325P
- (no CPE)range: 1.325P and prior
- (no CPE)range: 1.320J and prior
1.11M to 1.626C+ 2 more
- (no CPE)range: 1.11M to 1.626C
- (no CPE)range: 1.11M to 1.626C
- (no CPE)range: 1.106L and prior
4.00A to 5.007H+ 1 more
- (no CPE)range: 4.00A to 5.007H
- (no CPE)range: 4.00A to 5.007H
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3- www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-020_en.pdfmitrevendor-advisory
- jvn.jp/vu/JVNVU95103362mitregovernment-resource
- www.cisa.gov/news-events/ics-advisories/icsa-24-030-02mitregovernment-resource
News mentions
0No linked articles in our index yet.