Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mitsubishielectric

First CVE: Mar 28, 2008Active for: 18 yearsTotal CVEs: 163
51.0
VTI Score
TOP TARGET

Mitsubishi Electric's vulnerability footprint spans a very large portfolio of industrial automation, control, and engineering software products that support critical manufacturing and utility infrastructure globally, representing a high-value attack surface with outsized prominence in the vulnerability landscape. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes, reflecting the safety-sensitive and command-execution contexts of industrial control software. The exposure recurs across products such as GX Works3, GX Works2, GT SoftGOT2000, EZSocket, and CW Configurator through weakness classes including uncontrolled resource consumption, hard-coded credentials, improper input validation, and untrusted deserialization—patterns characteristic of engineering tools and runtime environments where operational uptime and legacy compatibility often outweigh memory-safe and defense-in-depth design. Defenders should prioritize inventory and isolation of these engineering platforms, particularly those exposed to untrusted networks, and treat this vendor's advisories as security-critical despite the limited public exploit activity typically observed in industrial settings. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
163
Total CVEs
More Total CVEs than 100% of tracked vendors
0.0
Avg CVEs / Product / Year
Bottom 1%
7.8
Avg CVSS Score
Higher Avg CVSS Score than 74% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mitsubishielectric over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 28, 2008
18 years ago
Most Recent CVE
Mar 3, 2026
147 days ago

Products(1,020 total)

Top CVEs

Signals from CVEs in this vendor scope (163 CVEs).

163 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2019-14931CRITICAL
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote OS Command Injection vulnerabi
Oct 28, 20199.872NOYES
CVE-2022-33318CRITICAL
Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 t
Jul 20, 20229.856NONO
CVE-2019-14927HIGH
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote configuration download vulnera
Oct 28, 20197.556NOYES
CVE-2018-16060HIGH
Mitsubishi Electric Europe B.V. SmartRTU devices allow remote attackers to obtain sensitive information (directory listing and source code) via a direct request to the /web URI.
Oct 15, 20217.545NOYES
CVE-2019-14928MEDIUM
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A number of stored cross-site script (XSS) vulnerabiliti
Oct 28, 20195.439NONO
CVE-2020-12011CRITICAL
A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition or allow remote code execution. This issue affects: Mitsubishi Elect
Jul 16, 20209.838NONO
CVE-2013-2817HIGH
An ActiveX control in IcoLaunch.dll in Mitsubishi Electric Automation MC-WorX Suite 8.02 allows user-assisted remote attackers to execute arbitrary programs via a crafted HTML docu
Feb 24, 20149.335NOYES
CVE-2018-16061MEDIUM
Mitsubishi Electric Europe B.V. SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php.
Oct 15, 20216.132NOYES
CVE-2021-20588CRITICAL
Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, C
Feb 19, 20219.832NONO
CVE-2022-33321CRITICAL
Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Electric consumer electronics products (PHOT
Nov 8, 20229.831NONO
View all 163 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products163 CVEs
21%
51%
28%
Severity distribution among all CVEs353,173 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local30 (18.4%)
Network127 (77.9%)
Unknown3 (1.8%)
Physical0 (0.0%)
Adjacent Network3 (1.8%)
Attack Complexity
Low150 (92.0%)
High10 (6.1%)
Unknown3 (1.8%)
User Interaction
None142 (87.1%)
Unknown3 (1.8%)
Required18 (11.0%)
Privileges Required
Low23 (14.1%)
High0 (0.0%)
None137 (84.0%)
Unknown3 (1.8%)

Exploit Exposure

Signals from CVEs in this vendor scope (163 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
5 CVEs
3.1% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mitsubishielectric.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mitsubishielectric — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mitsubishielectric's Products

View all 4 CNAs →

Top CWEs