Buffer Over-read Vulnerability in Mitsubishi Electric MC Works64 and ICONICS Products
CVE-2022-23130

5.9MEDIUM

What is CVE-2022-23130?

A buffer over-read vulnerability exists in Mitsubishi Electric's MC Works64 and ICONICS software, enabling an attacker to potentially induce a Denial of Service (DoS) condition. This can occur when a legitimate user unwittingly imports a maliciously crafted configuration file containing stored procedures into the GENESIS64 or MC Works64 applications. Successful exploitation allows attackers to execute unauthorized commands against the database, disrupting normal operations and service availability. It is crucial for users to apply recommended security patches and review configurations to mitigate potential risks.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

GENESIS32 Versions 9.7 or prior

GENESIS32 Versions 9.7 or prior

GENESIS64 Versions 10.97 and prior

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
High
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.