Our takeCISA reports active exploitation in Mitsubishi Electric GX Works3 and Motion Control Settings: a local attacker can bypass an invalid block password, modify the executable in memory, and view/tamper with/destroy control programs. Update affected versions immediately.Cyber Resilience desk
Sources (2)
- cisa_advisories · cisa_advisories
- cisa_ics · cisa_ics
What this means for you — Security leader:CISA reports active exploitation of a local authentication bypass in Mitsubishi Electric GX Works3 and Motion Control Settings that lets an attacker with code execution modify memory and access or alter control programs. Update affected versions immediately if you run them in production OT environments.
What this means for you — Lean IT orgs:If you run Mitsubishi Electric GX Works3 or Motion Control Settings on any PC connected to your equipment, check the CISA advisory for your exact version and apply the vendor update right away. This is a local attack but it can let someone tamper with or delete your control programs.
What this means for you — MSP:Scan client environments for any use of Mitsubishi Electric GX Works3 or Motion Control Settings; the listed versions have a confirmed local authentication bypass that permits in-memory modification of control programs. Patch or isolate affected engineering workstations across your customer base.
What this means for you — Researcher:CISA advisory ICSA-26-260-02 details a local authentication bypass in Mitsubishi Electric GX Works3 and Motion Control Settings allowing invalid block passwords to succeed via in-memory executable modification, leading to full control-program access.