CVE-2024-25086: Code Injection
Published Jul 2, 2024
·Updated
Improper privilege management in Jungo WinDriver before 12.2.0 allows local attackers to escalate privileges and execute arbitrary code.
Affected Software
43 affected components
Jungo Windriver<12.2.0
Mitsubishielectric Cpu Module Logging Configuration Tool
Mitsubishielectric Cw Configurator
Mitsubishielectric Data Transfer
Mitsubishielectric Data Transfer Classic
Mitsubishielectric Ezsocket
Mitsubishielectric Fr Configurator Sw3
Mitsubishielectric Fr Configurator2
Mitsubishielectric Genesis64
Mitsubishielectric Gt Got1000
Mitsubishielectric Gt Got2000
Mitsubishielectric Gt Softgot1000
Mitsubishielectric Gt Softgot2000
Mitsubishielectric Gx Developer
Mitsubishielectric Gx Logviewer
Mitsubishielectric Gx Works2
Mitsubishielectric Gx Works3
Mitsubishielectric Iq Works
Mitsubishielectric Mi Configurator
Mitsubishielectric Mr Configurator
Mitsubishielectric Mr Configurator2
Mitsubishielectric Mx Component
Mitsubishielectric Mx Opc Server Da\/ua
Mitsubishielectric Numerical Control Device Communication
Mitsubishielectric Px Developer\/monitor Tool
Mitsubishielectric Rt Toolbox3
Mitsubishielectric Rt Visualbox
All of the following
Mitsubishielectric Mrzjw3-mc2-utl Firmware
Mitsubishielectric Mrzjw3-mc2-utl
All of the following
Mitsubishielectric Sw0dnc-mneth-b Firmware
Mitsubishielectric Sw0dnc-mneth-b
All of the following
Mitsubishielectric Sw1dnc-ccbd2-b Firmware
Mitsubishielectric Sw1dnc-ccbd2-b
All of the following
Mitsubishielectric Sw1dnc-ccief-j Firmware
Mitsubishielectric Sw1dnc-ccief-j
All of the following
Mitsubishielectric Sw1dnc-ccief-b Firmware
Mitsubishielectric Sw1dnc-ccief-b
All of the following
Mitsubishielectric Sw1dnc-mnetg-b Firmware
Mitsubishielectric Sw1dnc-mnetg-b
All of the following
Mitsubishielectric Sw1dnc-qsccf-b Firmware
Mitsubishielectric Sw1dnc-qsccf-b
All of the following
Mitsubishielectric Sw1dnd-emsdk-b Firmware
Mitsubishielectric Sw1dnd-emsdk-b
Event History
Jul 2, 2024
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2024-25086?
CVE-2024-25086 is classified with a high severity due to its potential for privilege escalation and arbitrary code execution.
2
What are the potential impacts of CVE-2024-25086?
The impact of CVE-2024-25086 includes unauthorized access and control over the affected systems, leading to security breaches.
3
How do I fix CVE-2024-25086?
To resolve CVE-2024-25086, users should update to Jungo WinDriver version 12.2.0 or later.
4
Which software is affected by CVE-2024-25086?
CVE-2024-25086 affects Jungo WinDriver versions prior to 12.2.0 and multiple Mitsubishi Electric software products.
5
Who is at risk of CVE-2024-25086?
Local attackers with access to the affected systems are at risk of exploiting CVE-2024-25086.