CVE-2023-5275 LOW

CVE-2023-5275

Vendor Mitsubishi Electric Corporation
Product GX Works2
Weakness CWE-20 · Input validation
Published November 21, 2023
Last update February 25, 2026

CVSS base score

2.5/10
Attack vector Local
Attack complexity High
Privileges required Low
User interaction None
Confidentiality None
Integrity None

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:L

What the vulnerability does

01Description

Improper Input Validation vulnerability in simulation function of GX Works2 allows an attacker to cause a denial-of-service (DoS) condition on the function by sending specially crafted packets. However, the attacker would need to send the packets from within the same personal computer where the function is running.

Key dates

02Disclosure timeline

November 21, 2023 CVE published
February 25, 2026 Record updated