CVE-2025-11009 MEDIUM

CVE-2025-11009: Information Disclosure Vulnerability in GT Designer3

Vendor Mitsubishi Electric Corporation
Product GT Designer3 Version1 (GOT2000)
Weakness CWE-312 · Cleartext storage
Published December 17, 2025
Last update December 17, 2025

CVSS base score

5.1/10
Attack vector Local
Attack complexity High
Privileges required None
User interaction None
Confidentiality High
Integrity None

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

What the vulnerability does

01Description

Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GT Designer3 Version1 (GOT2000) all versions and Mitsubishi Electric GT Designer3 Version1 (GOT1000) all versions allows a local unauthenticated attacker to obtain plaintext credentials from the project file for GT Designer3. This could allow the attacker to operate illegally GOT2000 series or GOT1000 series by using the obtained credentials.

Key dates

02Disclosure timeline

December 17, 2025 CVE published
December 17, 2025 Record updated