ZeroHour
Organization

Mitsubishi Electric

2 mentions in 7 days · 2 in 30 days · 2 total · first seen · last

Timeline

Mitsubishi Electric GX Works3 and Motion Control Settings

CISA warns CVE-2026-15688 lets a local attacker bypass block password authentication in Mitsubishi Electric GX Works3 and tamper with control programs.

CISA republished Mitsubishi Electric advisory 2026-007 describing CVE-2026-15688, an incorrect implementation of the authentication algorithm (CWE-303) in GX Works3 and the bundled Motion Control Settings, affecting all versions. A local attacker can authenticate with an invalid block password, modify an executable module in memory, and view, tamper with, destroy, or delete control programs. CVSS v3.1 base score is 8.8 (v4.0: 9.2), and CISA recommends isolating control system networks and minimizing internet exposure.

Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A)

CISA updated its CC-Link IE TSN advisory: segment-attached attackers can tamper with Mitsubishi Electric control data and trigger denial of service conditions.

CISA updated its advisory (ICSA-26-211-07 Update A) on a CWE-924 improper enforcement of message integrity flaw in the Mitsubishi Electric CC-Link IE TSN communication protocol. An attacker on the same network segment can send specially crafted packets under specific timing conditions to tamper with control input and output values, causing incorrect operation or denial of service in affected products. Affected products span numerous models, including MELSEC MX controllers, RJ71GN11 modules, motion modules (RD78G/LD78G), FX5 units, and NZ2GN block-type remote modules.

CISA Advisories · 1d agoAdvisory 2 sources

Related CVEs

  • Block password bypass in Mitsubishi Electric GX Works3 and Motion Control Setting
    Mitsubishi Electric's GX Works3 and Motion Control Setting engineering software implement the block password feature incorrectly (CWE-303), so authentication succeeds even with an invalid password. A local attacker with low privileges who can execute the affected software can modify part of the executable module in memory to bypass the password check. Once bypassed, the attacker can view, tamper with, destroy, or delete PLC control programs that the password was meant to protect. Any organization running the affected software on engineering workstations with access to MELSEC PLC environments is affected, since the attack requires only local access to the workstation. No public proof-of-concept or in-the-wild exploitation is known, and the issue is not listed in CISA KEV.
    · Mitsubishi Electric GX Works3 · Mitsubishi Electric Motion Control Settinglarge

Appears with

Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.