Remote SQL Command Execution Vulnerability in Mitsubishi Electric and ICONICS Products
CVE-2020-12013

9.1CRITICAL

What is CVE-2020-12013?

This vulnerability allows an attacker to exploit a specially crafted WCF client to execute arbitrary SQL commands remotely. The impact is felt in several Mitsubishi Electric and ICONICS products, which could lead to unauthorized data manipulation or access. Versions vulnerable include Mitsubishi Electric MC Works64 prior to version 4.02C and MC Works32 version 3.00A, as well as ICONICS products such as GenBroker64 and GenBroker32 across specific versions. Organizations using these products should take immediate action to mitigate the risk associated with this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

GenBroker32 v9.5 and prior

GenBroker64, Platform Services, Workbench, FrameWorX Server v10.96 and prior

MC Works32 Version 3.00A (9.50.255.02)

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.