CVE-2024-8300: Malicious Code Execution Vulnerability in GENESIS64 and ICONICS Suite
Dead Code vulnerability in Mitsubishi Electric GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3, Mitsubishi Electric Iconics Digital Solutions GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3, Mitsubishi Electric ICONICS Suite Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3, and Mitsubishi Electric Iconics Digital Solutions ICONICS Suite Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3 allows a local authenticated attacker to execute a malicious code by tampering with a specially crafted DLL. This could lead to disclose, tamper with, destroy, or delete information in the affected products, or cause a denial of service (DoS) condition on the products.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-8300?
The severity of CVE-2024-8300 is rated as high due to the potential for local authenticated attackers to execute arbitrary code.
How do I fix CVE-2024-8300?
To fix CVE-2024-8300, users should update to the latest patched version of ICONICS GENESIS64 or Mitsubishi Electric GENESIS64.
Who is affected by CVE-2024-8300?
CVE-2024-8300 affects users of ICONICS GENESIS64 and Mitsubishi Electric GENESIS64 versions 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2, and 10.97.3.
What type of vulnerability is CVE-2024-8300?
CVE-2024-8300 is categorized as a dead code vulnerability, which can be exploited by attackers to execute malicious code.
What are the potential risks of CVE-2024-8300?
The potential risks of CVE-2024-8300 include unauthorized code execution and potential system compromise if exploited by attackers.