VDB

CVE-2024-1182

CVE-2024-1182 PUBLISHED CVSS 7 HIGH

Uncontrolled Search Path Element vulnerability in ICONICS GENESIS64 all versions, Mitsubishi Electric GENESIS64 all versions and Mitsubishi Electric MC Works64 all versions allows a local attacker to execute a malicious code by storing a specially crafted DLL in a specific folder when GENESIS64 and MC Works64 are installed with the Pager agent in the alarm multi-agent notification feature.

EPSS 0.26% · 16.0th percentile

Risk Scores

CVSS 3.1
7
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.26%
16.0th percentile

Affected Products

VendorProductVersions
Mitsubishi Electric Iconics Digital SolutionsGENESIS32*, versions 9.7 and prior
Mitsubishi Electric CorporationICONICS Suite10.97.3 and prior, all versions
iconicsgenesis640, 0
Mitsubishi Electric CorporationMC Works64all versions, all versions
Mitsubishi Electric CorporationHyper Historian10.97.3 and prior
Mitsubishi Electric CorporationGENESIS6410.97.3 and prior, *
Mitsubishi Electric Iconics Digital SolutionsHyper Historian10.97.3 and prior
mitsubishielectricmc_works640, 0
Mitsubishi Electric Iconics Digital SolutionsICONICS Suiteall versions, 10.97.3 and prior
Mitsubishi Electric Iconics Digital SolutionsGENESIS64*, 10.97.3 and prior
Mitsubishi Electric CorporationGENESIS32versions 9.7 and prior, all versions

Timeline

  • Jul 4, 2024 CVE Published
  • Jul 5, 2024 EPSS Score
  • Jul 27, 2024 EPSS Score
  • Aug 23, 2024 EPSS Score
  • Sep 14, 2024 EPSS Score
  • Oct 4, 2024 Coalition ESS Score
  • Oct 7, 2024 EPSS Score
  • Oct 29, 2024 EPSS Score
  • Nov 20, 2024 EPSS Score
  • Dec 14, 2024 EPSS Score
  • Jan 5, 2025 EPSS Score
  • Jan 28, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›