PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-3784 Mitsubishi Electric CVE debrief

A medium-severity vulnerability in Mitsubishi Electric GX Works2 allows credential disclosure from plaintext storage in project files. An attacker with local access can extract authentication credentials and bypass project file protections to view or modify industrial control system configurations. No patch is currently available; CISA and Mitsubishi Electric recommend network segmentation, physical access controls, and encryption of project files during transfer.

Vendor
Mitsubishi Electric
Product
GX Works2
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2025-12-04
Original CVE updated
2025-12-04
Advisory published
2025-12-04
Advisory updated
2025-12-04

Who should care

Industrial control system engineers, OT security teams, and manufacturing organizations using Mitsubishi Electric GX Works2 for PLC programming should prioritize this vulnerability. Organizations with distributed engineering teams or remote access to programming workstations face elevated risk. Asset owners in critical infrastructure sectors should review project file handling procedures and implement compensating controls until vendor patches are released.

Technical summary

CVE-2025-3784 affects Mitsubishi Electric GX Works2 engineering software used for programming Mitsubishi PLCs. The vulnerability stems from storing authentication credentials in plaintext within project files. An attacker with local access to a workstation or project file can extract these credentials and use them to open password-protected project files, potentially viewing or modifying industrial control logic. The CVSS 3.1 score of 5.5 reflects a local attack vector with low attack complexity and high confidentiality impact, but no integrity or availability impact on the software itself. CISA advisory ICSA-25-338-01 confirms no patched version is currently available. Mitigations focus on access controls, network segmentation, and encryption of project files during transfer.

Defensive priority

medium

Recommended defensive actions

  • Restrict physical and network access to engineering workstations running GX Works2; deploy host-based firewalls to block remote logins from untrusted sources
  • Segment affected systems from untrusted networks using firewalls or VPNs; limit remote access to authenticated, authorized personnel only
  • Encrypt project files when transmitting over any network to prevent credential exposure in transit
  • Monitor for unauthorized access attempts to GX Works2 workstations and project file directories
  • Apply security updates from Mitsubishi Electric when available; reference vendor security bulletin for patch release timing
  • Implement defense-in-depth controls per CISA ICS recommended practices including antivirus deployment on engineering workstations

Evidence notes

CISA published advisory ICSA-25-338-01 on 2025-12-04 confirming plaintext credential storage in GX Works2 project files. CVSS 3.1 vector AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N indicates local attack vector with low complexity and high confidentiality impact. Mitsubishi Electric confirms fixed version is under development.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-3784 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-3784

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-3784 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-3784

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-338-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-338-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/news/targeted-cyber-intrusion-detection-and-mitigation-strategies-update-b

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.