5.5
/ 10
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Description
Cleartext Storage of Sensitive Information Vulnerability in GX Works2 all versions allows an attacker to disclose credential information stored in plaintext from project files. As a result, the attacker may be able to open project files protected by user authentication using disclosed credential information, and obtain or modify project information.
Basic Information
ID
CVE-2025-3784
Source
Mitsubishi
Published
Nov 27, 2025 at 04:28
Affected Product
Vendor
Mitsubishi Electric Corporation
Product
GX Works2
Version
All versions
Affected Versions
Mitsubishi Electric Corporation GX Works2 All versions