Deserialization Vulnerability in ICONICS GENESIS64 and Mitsubishi Electric MC Works64
CVE-2022-33315

7.8HIGH

Key Information:

Vendor

Iconics

Vendor
CVE Published:
20 July 2022

What is CVE-2022-33315?

A deserialization vulnerability in ICONICS GENESIS64 and Mitsubishi Electric MC Works64 exposes these products to attacks where unauthenticated users can execute arbitrary malicious code. This occurs when a user is manipulated into loading a monitoring screen file that contains malicious XAML codes. Such vulnerabilities can lead to a significant security breach, allowing attackers to compromise systems and potentially exploit further vulnerabilities.

Affected Version(s)

ICONICS GENESIS64; Mitsubishi Electric MC Works64 ICONICS GENESIS64 versions 10.97.1 and prior

ICONICS GENESIS64; Mitsubishi Electric MC Works64 Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.