Lucene search

K
cveMitsubishiCVE-2022-33317
HistoryJul 20, 2022 - 5:15 p.m.

CVE-2022-33317

2022-07-2017:15:08
CWE-829
Mitsubishi
web.nvd.nist.gov
43
3
cve
iconics genesis64
mitsubishi electric mc works64
code execution
security vulnerability

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

34.5%

Inclusion of Functionality from Untrusted Control Sphere vulnerability in ICONICS GENESIS64 versions 10.97.1 and prior and Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior allows an unauthenticated attacker to execute an arbitrary malicious code by leading a user to load a monitoring screen file including malicious script codes.

Affected configurations

Nvd
Node
iconicsgenesis64Match10.97
OR
iconicsgenesis64Match10.97.1
Node
mitsubishielectricmc_works64Range10.95.210.01
VendorProductVersionCPE
iconicsgenesis6410.97cpe:2.3:a:iconics:genesis64:10.97:*:*:*:*:*:*:*
iconicsgenesis6410.97.1cpe:2.3:a:iconics:genesis64:10.97.1:*:*:*:*:*:*:*
mitsubishielectricmc_works64*cpe:2.3:a:mitsubishielectric:mc_works64:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "ICONICS GENESIS64; Mitsubishi Electric MC Works64",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "ICONICS GENESIS64 versions 10.97.1 and prior"
      },
      {
        "status": "affected",
        "version": "Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior"
      }
    ]
  }
]

Social References

More

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS

0.001

Percentile

34.5%

Related for CVE-2022-33317