Possible Local Authenticated Attack leading to Information Disclosure or Denial of Service
CVE-2024-8300

7HIGH

Key Information:

Status
Vendor
CVE Published:
28 November 2024

Summary

A dead code vulnerability has been identified in the GENESIS64 software from both ICONICS and Mitsubishi Electric that impacts several versions. This issue allows local authenticated attackers to execute malicious code by manipulating a specially crafted Dynamic Link Library (DLL). Exploitation of this vulnerability could lead to unauthorized disclosure of information, tampering, destruction, or deletion of data. Furthermore, the vulnerability poses a risk of causing denial of service conditions on the affected products, potentially disrupting normal operations.

Affected Version(s)

GENESIS64 Version 10.97.2

GENESIS64 10.97.2 CFR1

GENESIS64 10.97.2 CRF2

References

CVSS V3.1

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

Credit

Asher Davila of Palo Alto Networks
Malav Vyas of Palo Alto Networks
.