Cleartext Storage of Sensitive Information Vulnerability in GX Works2 all versions allows an attacker to disclose credential information stored in plaintext from project files. As a result, the attacker may be able to open project files protected by user authentication using disclosed credential information, and obtain or modify project information.
History

Fri, 28 Nov 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 27 Nov 2025 16:30:00 +0000

Type Values Removed Values Added
First Time appeared Mitsubishielectric
Mitsubishielectric gx Works2
Vendors & Products Mitsubishielectric
Mitsubishielectric gx Works2

Thu, 27 Nov 2025 04:45:00 +0000

Type Values Removed Values Added
Description Cleartext Storage of Sensitive Information Vulnerability in GX Works2 all versions allows an attacker to disclose credential information stored in plaintext from project files. As a result, the attacker may be able to open project files protected by user authentication using disclosed credential information, and obtain or modify project information.
Title Information Disclosure Vulnerability in GX Works2
Weaknesses CWE-312
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mitsubishi

Published: 2025-11-27T04:28:17.249Z

Updated: 2025-11-28T19:33:31.195Z

Reserved: 2025-04-18T02:21:50.076Z

Link: CVE-2025-3784

cve-icon Vulnrichment

Updated: 2025-11-28T14:39:34.316Z

cve-icon NVD

Status : Received

Published: 2025-11-27T05:16:15.467

Modified: 2025-11-27T05:16:15.467

Link: CVE-2025-3784

cve-icon Redhat

No data.