CVE-2020-12009: High severity Mitsubishi Electric MC Works64 Version 4.02C (10.95.208.31) and earlier, all versions vulnerability
A specially crafted communication packet sent to the affected device could cause a denial-of-service condition due to a deserialization vulnerability. This affects: Mitsubishi Electric MC Works64 Version 4.02C (10.95.208.31) and earlier, all versions; Mitsubishi Electric MC Works32 Version 3.00A (9.50.255.02); ICONICS GenBroker64, Platform Services, Workbench, FrameWorX Server v10.96 and prior; ICONICS GenBroker32 v9.5 and prior.
Affected Software
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is CVE-2020-12009?
CVE-2020-12009 is a vulnerability in Mitsubishi Electric MC Works64 and MC Works32, Iconics Energy Analytix, Facility Analytix, GENESIS64, Hyper Historian, MobileHMI, Quality Analytix, Smart Energy Analytix, ICONICS BizViz, and GENESIS32 that could cause a denial-of-service condition.
How does CVE-2020-12009 impact the affected devices?
CVE-2020-12009 could cause a denial-of-service condition on the affected devices due to a deserialization vulnerability.
What is the severity level of CVE-2020-12009?
CVE-2020-12009 has a severity level of 7.5 (high).
Which software versions are affected by CVE-2020-12009?
CVE-2020-12009 affects Mitsubishi Electric MC Works64 Version 4.02C and earlier, all versions; Mitsubishi Electric MC Works32 Version 3.00A (9.50.255.02); Iconics Energy Analytix; Iconics Facility Analytix; ICONICS GENESIS64; ICONICS Hyper Historian; ICONICS MobileHMI; Iconics Quality Analytix; Iconics Smart Energy Analytix; ICONICS BizViz; ICONICS GENESIS32.
How can I fix CVE-2020-12009?
To fix CVE-2020-12009, it is recommended to update to the latest version of the affected software as provided by Mitsubishi Electric or ICONICS.