Lucene search

K
cveMitsubishiCVE-2022-23129
HistoryJan 21, 2022 - 7:15 p.m.

CVE-2022-23129

2022-01-2119:15:10
CWE-312
Mitsubishi
web.nvd.nist.gov
48
cve-2022-23129
mitsubishi electric
mc works64
iconics
genesis64
plaintext storage
password vulnerability
database security
authentication
nvd

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.5

Confidence

High

EPSS

0

Percentile

5.3%

Plaintext Storage of a Password vulnerability in Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior and ICONICS GENESIS64 versions 10.90 to 10.97 allows a local authenticated attacker to gain authentication information and to access the database illegally. This is because when configuration information of GridWorX, a database linkage function of GENESIS64 and MC Works64, is exported to a CSV file, the authentication information is saved in plaintext, and an attacker who can access this CSV file can gain the authentication information.

Affected configurations

Nvd
Node
iconicsgenesis64Range10.9010.97
OR
mitsubishielectricmc_works64Range<10.95.210.01
VendorProductVersionCPE
iconicsgenesis64*cpe:2.3:a:iconics:genesis64:*:*:*:*:*:*:*:*
mitsubishielectricmc_works64*cpe:2.3:a:mitsubishielectric:mc_works64:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Mitsubishi Electric MC Works64; ICONICS GENESIS64",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior"
      },
      {
        "status": "affected",
        "version": "ICONICS GENESIS64 versions 10.90 to 10.97"
      }
    ]
  }
]

CVSS2

2.1

Attack Vector

LOCAL

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:L/AC:L/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

AI Score

5.5

Confidence

High

EPSS

0

Percentile

5.3%

Related for CVE-2022-23129