CVE-2020-12007: Critical severity mitsubishi electric mc works64 vulnerability
A specially crafted communication packet sent to the affected devices could allow remote code execution and a denial-of-service condition due to a deserialization vulnerability. This issue affects: Mitsubishi Electric MC Works64 version 4.02C (10.95.208.31) and earlier, all versions; Mitsubishi Electric MC Works32 version 3.00A (9.50.255.02); ICONICS GenBroker64, Platform Services, Workbench, FrameWorX Server version 10.96 and prior; ICONICS GenBroker32 version 9.5 and prior.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-12007?
CVE-2020-12007 is a vulnerability that allows remote code execution and denial-of-service in Mitsubishi Electric MC Works64 version 4.02C and earlier, as well as other affected software.
How severe is CVE-2020-12007?
CVE-2020-12007 has a severity rating of 9.8 (critical).
How can CVE-2020-12007 be exploited?
CVE-2020-12007 can be exploited by sending a specially crafted communication packet to the affected devices.
What is the impact of CVE-2020-12007?
The impact of CVE-2020-12007 includes remote code execution and a denial-of-service condition.
How can I fix CVE-2020-12007?
To fix CVE-2020-12007, it is recommended to update to a version that is not affected by the vulnerability.