Mitsubishi Electric's vulnerability footprint spans a very large portfolio of industrial automation, control, and engineering software products that support critical manufacturing and utility infrastructure globally, representing a high-value attack surface with outsized prominence in the vulnerability landscape. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, reflecting the safety-sensitive and command-execution contexts of industrial control software. The exposure recurs across products such as GX Works3, GX Works2, GT SoftGOT2000, EZSocket, and CW Configurator through weakness classes including uncontrolled resource consumption, hard-coded credentials, improper input validation, and untrusted deserialization—patterns characteristic of engineering tools and runtime environments where operational uptime and legacy compatibility often outweigh memory-safe and defense-in-depth design. Defenders should prioritize inventory and isolation of these engineering platforms, particularly those exposed to untrusted networks, and treat this vendor's advisories as security-critical despite the limited public exploit activity typically observed in industrial settings. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mitsubishielectric over time
Signals from CVEs in this vendor scope (163 CVEs).
163 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-14931CRITICAL An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote OS Command Injection vulnerabi | Oct 28, 2019 | 9.8 | 72 | NO | YES |
CVE-2022-33318CRITICAL Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 t | Jul 20, 2022 | 9.8 | 56 | NO | NO |
CVE-2019-14927HIGH An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote configuration download vulnera | Oct 28, 2019 | 7.5 | 56 | NO | YES |
CVE-2018-16060HIGH Mitsubishi Electric Europe B.V. SmartRTU devices allow remote attackers to obtain sensitive information (directory listing and source code) via a direct request to the /web URI. | Oct 15, 2021 | 7.5 | 45 | NO | YES |
CVE-2019-14928MEDIUM An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A number of stored cross-site script (XSS) vulnerabiliti | Oct 28, 2019 | 5.4 | 39 | NO | NO |
CVE-2020-12011CRITICAL A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition or allow remote code execution. This issue affects: Mitsubishi Elect | Jul 16, 2020 | 9.8 | 38 | NO | NO |
CVE-2013-2817HIGH An ActiveX control in IcoLaunch.dll in Mitsubishi Electric Automation MC-WorX Suite 8.02 allows user-assisted remote attackers to execute arbitrary programs via a crafted HTML docu | Feb 24, 2014 | 9.3 | 35 | NO | YES |
CVE-2018-16061MEDIUM Mitsubishi Electric Europe B.V. SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php. | Oct 15, 2021 | 6.1 | 32 | NO | YES |
CVE-2021-20588CRITICAL Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, C | Feb 19, 2021 | 9.8 | 32 | NO | NO |
CVE-2022-33321CRITICAL Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Electric consumer electronics products (PHOT | Nov 8, 2022 | 9.8 | 31 | NO | NO |
Signals from CVEs in this vendor scope (163 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mitsubishielectric.
Media articles that mention a CVE ID that affects a product developed by Mitsubishielectric — matched by CVE ID, not by vendor name.