Possible Local Authenticated Attack leading to Information Disclosure or Denial of Service
CVE-2024-8300
7HIGH
Key Information:
- Status
- Vendor
- CVE Published:
- 28 November 2024
Summary
A dead code vulnerability has been identified in the GENESIS64 software from both ICONICS and Mitsubishi Electric that impacts several versions. This issue allows local authenticated attackers to execute malicious code by manipulating a specially crafted Dynamic Link Library (DLL). Exploitation of this vulnerability could lead to unauthorized disclosure of information, tampering, destruction, or deletion of data. Furthermore, the vulnerability poses a risk of causing denial of service conditions on the affected products, potentially disrupting normal operations.
Affected Version(s)
GENESIS64 Version 10.97.2
GENESIS64 10.97.2 CFR1
GENESIS64 10.97.2 CRF2
References
CVSS V3.1
Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Credit
Asher Davila of Palo Alto Networks
Malav Vyas of Palo Alto Networks