CVE-2022-33319: Critical severity ICONICS GENESIS64 vulnerability
Out-of-bounds Read vulnerability in ICONICS GENESIS64 versions 10.97.1 and prior and Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior allows a remote unauthenticated attacker to disclose information on memory or cause a Denial of Service (DoS) condition by sending specially crafted packets to the GENESIS64 server.
Other sources
Out-of-bounds Read vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric ICONICS Suite versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97 to 10.97.1, Mitsubishi Electric GENESIS32 versions 9.7 and prior, Mitsubishi Electric Iconics Digital Solutions GENESIS32 versions 9.7 and prior, and Mitsubishi Electric MC Works64 versions 4.04E and prior allows a remote unauthenticated attacker to disclose information on memory or cause a Denial of Service (DoS) condition by sending specially crafted packets to the GENESIS64, ICONICS Suite, GENESIS32, or MC Works64 server.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-33319?
CVE-2022-33319 is an Out-of-bounds Read vulnerability in ICONICS GENESIS64 versions 10.97.1 and prior and Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior.
What is the severity of CVE-2022-33319?
The severity of CVE-2022-33319 is critical with a CVSS score of 9.1.
How does CVE-2022-33319 affect ICONICS GENESIS64?
CVE-2022-33319 affects ICONICS GENESIS64 versions 10.97.1 and prior.
How does CVE-2022-33319 affect Mitsubishi Electric MC Works64?
CVE-2022-33319 affects Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior.
How can I fix CVE-2022-33319?
To fix CVE-2022-33319, upgrade to a version later than 10.97.1 for ICONICS GENESIS64 and version later than 4.04E (10.95.210.01) for Mitsubishi Electric MC Works64.