CVE-2024-1182 PUBLISHED CVSS 7 HIGH

Uncontrolled Search Path Element vulnerability in Mitsubishi Electric Iconics Digital Solutions GENESIS64 all versions, Mitsubishi Electric GENESIS64 all versions, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite all versions, Mitsubishi Electric ICONICS Suite all versions, Mitsubishi Electric Iconics Digital Solutions GENESIS32 all versions, Mitsubishi Electric GENESIS32 all versions, and Mitsubishi Electric MC Works64 all versions allows a local attacker to execute a malicious code by storing a specially crafted DLL in a specific folder when GENESIS64, ICONICS Suite, GENESIS32, and MC Works64 are installed with the Pager agent in the alarm multi-agent notification feature.

EPSS 0.06% · 18.2th percentile

Risk Scores

CVSS v3.1
7
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.06%
18.2th percentile

Affected Products

VendorProductVersions
Mitsubishi Electric Iconics Digital SolutionsGENESIS32all versions
Mitsubishi Electric CorporationICONICS Suiteall versions
iconicsgenesis640
Mitsubishi Electric CorporationMC Works64all versions
Mitsubishi Electric CorporationGENESIS64all versions
mitsubishielectricmc_works640
Mitsubishi Electric Iconics Digital SolutionsICONICS Suiteall versions
Mitsubishi Electric Iconics Digital SolutionsGENESIS64all versions
Mitsubishi Electric CorporationGENESIS32all versions

Timeline

References

Open in Interactive Console →