First published: Wed Jul 20 2022(Updated: )
Deserialization of Untrusted Data vulnerability in ICONICS GENESIS64 versions 10.97.1 and prior and Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior allows an unauthenticated attacker to execute an arbitrary malicious code by leading a user to load a project configuration file including malicious XML codes.
Credit: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
Affected Software | Affected Version | How to fix |
---|---|---|
ICONICS GENESIS64 | =10.97 | |
ICONICS GENESIS64 | =10.97.1 | |
Mitsubishielectric Mc Works64 | <=10.95.210.01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-33320.
ICONICS GENESIS64 versions 10.97.1 and prior and Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior are affected by this vulnerability.
CVE-2022-33320 has a severity score of 7.8 (high).
An unauthenticated attacker can execute arbitrary malicious code by leading a user to load a project configuration file.
Upgrading to the latest version of ICONICS GENESIS64 and Mitsubishi Electric MC Works64 is recommended to fix CVE-2022-33320.