CVE-2022-33315: High severity ICONICS GENESIS64 vulnerability
Deserialization of Untrusted Data vulnerability in ICONICS GENESIS64 versions 10.97.1 and prior and Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior allows an unauthenticated attacker to execute an arbitrary malicious code by leading a user to load a monitoring screen file including malicious XAML codes.
Other sources
Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric ICONICS Suite versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97 to 10.97.1, and Mitsubishi Electric MC Works64 versions 4.04E and prior allows an unauthenticated attacker to execute an arbitrary malicious code by leading a user to load a monitoring screen file including malicious XAML codes.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-33315.
What is the affected software?
The affected software includes ICONICS GENESIS64 versions 10.97.1 and prior, and Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior.
What is the severity of CVE-2022-33315?
The severity of CVE-2022-33315 is high, with a CVSS score of 7.8.
How does CVE-2022-33315 work?
CVE-2022-33315 is a deserialization of untrusted data vulnerability that allows an unauthenticated attacker to execute arbitrary malicious code by leading a user to load a monitoring screen file that includes the attack payload.
Are there any references for CVE-2022-33315?
Yes, you can find more information about CVE-2022-33315 at the following references: - [JVN](https://jvn.jp/vu/JVNVU96480474/index.html) - [Mitsubishi Electric PSIRT](https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-008_en.pdf)