First published: Thu Jun 18 2020(Updated: )
A specially crafted communication packet sent to the affected device could cause a denial-of-service condition due to a deserialization vulnerability. This affects: Mitsubishi Electric MC Works64 Version 4.02C (10.95.208.31) and earlier, all versions; Mitsubishi Electric MC Works32 Version 3.00A (9.50.255.02); ICONICS GenBroker64, Platform Services, Workbench, FrameWorX Server v10.96 and prior; ICONICS GenBroker32 v9.5 and prior.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Mitsubishielectric Mc Works | <=10.95.208.31 | |
Mitsubishielectric Mc Works32 | =9.50.255.02 | |
Iconics Energy Analytix | ||
Iconics Facility Analytix | ||
ICONICS GENESIS64 | ||
ICONICS Hyper Historian | ||
ICONICS MobileHMI | ||
Iconics Quality Analytix | ||
Iconics Smart Energy Analytix | ||
ICONICS BizViz | ||
ICONICS GENESIS32 | ||
ICONICS GENESIS64 | ||
ICONICS Hyper Historian | ||
ICONICS AnalytiX | ||
ICONICS MobileHMI | ||
Mitsubishi Electric MC Works64 version 4.02C (10.95.208.31) and earlier, all versions | ||
Mitsubishi Electric MC Works32 version 3.00A (9.50.255.02) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-12009 is a vulnerability in Mitsubishi Electric MC Works64 and MC Works32, Iconics Energy Analytix, Facility Analytix, GENESIS64, Hyper Historian, MobileHMI, Quality Analytix, Smart Energy Analytix, ICONICS BizViz, and GENESIS32 that could cause a denial-of-service condition.
CVE-2020-12009 could cause a denial-of-service condition on the affected devices due to a deserialization vulnerability.
CVE-2020-12009 has a severity level of 7.5 (high).
CVE-2020-12009 affects Mitsubishi Electric MC Works64 Version 4.02C and earlier, all versions; Mitsubishi Electric MC Works32 Version 3.00A (9.50.255.02); Iconics Energy Analytix; Iconics Facility Analytix; ICONICS GENESIS64; ICONICS Hyper Historian; ICONICS MobileHMI; Iconics Quality Analytix; Iconics Smart Energy Analytix; ICONICS BizViz; ICONICS GENESIS32.
To fix CVE-2020-12009, it is recommended to update to the latest version of the affected software as provided by Mitsubishi Electric or ICONICS.