BlackTree Security · Infrastructure · Automation · AI

A Memory Edit Can Walk Straight Through GX Works3 Password Protection

A block password is intended to stop an unauthorised person from reading or changing an industrial control program. Mitsubishi Electric says a local attacker can bypass that protection by changing the engineering software in memory, then authenticate with a password that should fail.

CVE-2026-15688 affects all versions of GX Works3 and Motion Control Setting according to the vendor’s CVE record. A successful attacker may view, tamper with, destroy or delete control programs. The CVSS 4.0 score is 9.2, Critical.

This is a workstation attack, not an internet takeover

The published vector is local and requires low privileges. The attacker must execute the affected product and modify part of its executable module in memory. The advisory does not describe an unauthenticated remote compromise of a PLC.

That prerequisite is still consequential. Engineering workstations often contain project files, network paths and access to production controllers. Malware or an unauthorised user already present on the workstation may use the bypass to cross a second boundary that operators expected the block password to enforce.

Mitsubishi’s mitigation changes the project security version

Mitsubishi’s advisory directs GX Works3 users to install version 1.096A or later and set the project security version to 2. That second step matters. Updating the application alone may not convert an existing project’s protection model. Organisations using Motion Control Setting should follow the product-specific instructions in the vendor advisory.

No exploitation is recorded in CISA’s Known Exploited Vulnerabilities catalogue, and the reviewed sources do not establish a public exploit campaign. This is a high-impact trust-boundary failure with local prerequisites, not evidence of active attacks.

Protect the engineering path, not only the PLC

  • Inventory engineering stations. Include laptops, jump hosts, vendor systems and offline maintenance machines.
  • Update the software and projects. Verify the installed GX Works3 build and the security version applied to each project.
  • Restrict local execution. Limit who can run debuggers, memory tools and unapproved software on engineering endpoints.
  • Monitor project changes. Compare control programs with approved versions and retain signing or checksum evidence where supported.
  • Separate credentials. Do not allow compromise of a normal user account to supply unrestricted controller administration.
  • Investigate before restoring. If project integrity is uncertain, preserve the workstation and controller evidence before overwriting it.

The core lesson is that password protection inside an engineering application cannot replace endpoint integrity. When the local process can be altered, the attacker may change the very code responsible for deciding whether the password is correct.

Sources

Leave a Reply

Your email address will not be published. Required fields are marked *