VDB

CVE-2024-1182

CVE-2024-1182 PUBLISHED CVSS 7 HIGH

Uncontrolled Search Path Element vulnerability in ICONICS GENESIS64 all versions, Mitsubishi Electric GENESIS64 all versions and Mitsubishi Electric MC Works64 all versions allows a local attacker to execute a malicious code by storing a specially crafted DLL in a specific folder when GENESIS64 and MC Works64 are installed with the Pager agent in the alarm multi-agent notification feature.

EPSS 0.11% · 28.7th percentile

Risk Scores

CVSS 3.1
7
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.11%
28.7th percentile

Affected Products

VendorProductVersions
Mitsubishi Electric Iconics Digital SolutionsGENESIS32*, versions 9.7 and prior
Mitsubishi Electric CorporationICONICS Suite10.97.3 and prior, all versions
iconicsgenesis640, 0
Mitsubishi Electric CorporationMC Works64all versions, all versions
Mitsubishi Electric CorporationHyper Historian10.97.3 and prior
Mitsubishi Electric CorporationGENESIS6410.97.3 and prior, *
Mitsubishi Electric Iconics Digital SolutionsHyper Historian10.97.3 and prior
mitsubishielectricmc_works640, 0
Mitsubishi Electric Iconics Digital SolutionsICONICS Suiteall versions, 10.97.3 and prior
Mitsubishi Electric Iconics Digital SolutionsGENESIS64*, 10.97.3 and prior
Mitsubishi Electric CorporationGENESIS32versions 9.7 and prior, all versions

Timeline

  • Jul 4, 2024 CVE Published
  • Jul 5, 2024 EPSS Score
  • Jul 27, 2024 EPSS Score
  • Aug 22, 2024 EPSS Score
  • Sep 13, 2024 EPSS Score
  • Oct 4, 2024 Coalition ESS Score
  • Oct 5, 2024 EPSS Score
  • Oct 27, 2024 EPSS Score
  • Nov 18, 2024 EPSS Score
  • Dec 11, 2024 EPSS Score
  • Jan 2, 2025 EPSS Score
  • Jan 24, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›