CVE-2025-11009
Information Disclosure Vulnerability in GT Designer3
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.1EPSS 0.1%KEV nãoPoC —Nuclei —Metasploit —Patch referenciado
Lifecycle
17 Dec 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GT Designer3 Version1 (GOT2000) all versions and Mitsubishi Electric GT Designer3 Version1 (GOT1000) all versions allows a local unauthenticated attacker to obtain plaintext credentials from the project file for GT Designer3. This could allow the attacker to operate illegally GOT2000 series or GOT1000 series by using the obtained credentials.
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Affected products
Mitsubishi Electric Corporation · GT Designer3 Version1 (GOT1000)Mitsubishi Electric Corporation · GT Designer3 Version1 (GOT2000)Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →