Записи ICONICS
33 опубликованных записей вендора iconics.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 1 · 3 %
- Pre-auth RCE
- 8
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-502 Deserialization of Untrusted Data7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-427 Uncontrolled Search Path Element3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-125 Out-of-bounds Read2
- CWE-787 Out-of-bounds Write2
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
33 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
53В плане | CVE-2022-33318Эксплойта нет | Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digiiconics · genesis64 · CWE-502 | Критическая9,8 | — | 48,1 % | 20 июл. 2022 г. |
48В плане | CVE-2011-2089Готовый эксплойт | Stack-based buffer overflow in the SetActiveXGUID method in the VersionInfo ActiveX control in GenVersion.dll 8.0.138.0 in the WebHMI subsysiconics · bizviz · CWE-119 | Критическая9,3 | — | 38,3 % | 13 мая 2011 г. |
48В плане | CVE-2020-12011Эксплойта нет | A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition or allow remote code executimitsubishielectric · mc works · CWE-787 | Критическая9,8 | — | 29,2 % | 16 июл. 2020 г. |
41В плане | CVE-2011-5089Эксплойта нет | Buffer overflow in the Security Login ActiveX controls in ICONICS GENESIS32 8.05, 9.0, 9.1, and 9.2 and BizViz 8.05, 9.0, 9.1, and 9.2 allowiconics · genesis32 · CWE-119 | Критическая10,0 | — | 4,3 % | 18 апр. 2012 г. |
40В плане | CVE-2020-12007Эксплойта нет | A specially crafted communication packet sent to the affected devices could allow remote code execution and a denial-of-service condition dumitsubishielectric · mc works · CWE-502 | Критическая9,8 | — | 3,9 % | 16 июл. 2020 г. |
40В плане | CVE-2022-23128Эксплойта нет | Incomplete List of Disallowed Inputs vulnerability in Mitsubishi Electric MC Works64 versions 4.00A (10.95.201.23) to 4.04E (10.95.210.01), iconics · analytix | Критическая9,8 | — | 2,9 % | 21 янв. 2022 г. |
38Наблюдать | CVE-2011-5088Эксплойта нет | The GENESIS32 IcoSetServer ActiveX control in ICONICS GENESIS32 9.21 and BizViz 9.21 configures the trusted zone on the basis of user input,iconics · bizviz | Критическая9,3 | — | 2,7 % | 18 апр. 2012 г. |
38Наблюдать | CVE-2014-0758Эксплойта нет | ICONICS GENESIS32 Exposed Dangerous Method or Functioniconics · genesis32 · CWE-749 | Критическая9,3 | — | 1,9 % | 24 февр. 2014 г. |
37Наблюдать | CVE-2020-12013Эксплойта нет | A specially crafted WCF client that interfaces to the may allow the execution of certain arbitrary SQL commands remotely.mitsubishielectric · mc works32 · CWE-94 | Критическая9,1 | — | 3,0 % | 16 июл. 2020 г. |
36Наблюдать | CVE-2022-33319Эксплойта нет | Out-of-bounds Read vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions Giconics · genesis64 · CWE-125 | Критическая9,1 | — | 1,6 % | 20 июл. 2022 г. |
32Наблюдать | CVE-2006-6488Proof of concept | Stack-based buffer overflow in the DoModal function in the Dialog Wrapper Module ActiveX control (DlgWrapper.dll) before 8.4.166.0, as used iconics · dialog wrapper module activex control | Высокая7,5 | — | 7,8 % | 31 дек. 2006 г. |
32Наблюдать | CVE-2021-27041Эксплойта нет | A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files.autodesk · advance steel · CWE-787 | Высокая7,8 | — | 1,7 % | 25 июн. 2021 г. |
31Наблюдать | CVE-2020-12009Эксплойта нет | A specially crafted communication packet sent to the affected device could cause a denial-of-service condition due to a deserialization vulnmitsubishielectric · mc works · CWE-502 | Высокая7,5 | — | 3,6 % | 16 июл. 2020 г. |
31Наблюдать | CVE-2016-2289Эксплойта нет | Directory traversal vulnerability in ICONICS WebHMI 9 and earlier allows remote attackers to read configuration files, and consequently disciconics · webhmi · CWE-22 | Высокая7,5 | — | 2,4 % | 1 апр. 2016 г. |
31Наблюдать | CVE-2020-12015Эксплойта нет | A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition due to improper deserializatmitsubishielectric · mc works · CWE-502 | Высокая7,5 | — | 2,0 % | 16 июл. 2020 г. |
31Наблюдать | CVE-2022-33320Эксплойта нет | Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digiiconics · genesis64 · CWE-502 | Высокая7,8 | — | 0,5 % | 20 июл. 2022 г. |
31Наблюдать | CVE-2022-33316Эксплойта нет | Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digiiconics · genesis64 · CWE-502 | Высокая7,8 | — | 0,3 % | 20 июл. 2022 г. |
31Наблюдать | CVE-2022-33315Эксплойта нет | Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digiiconics · genesis64 · CWE-502 | Высокая7,8 | — | 0,3 % | 20 июл. 2022 г. |
31Наблюдать | CVE-2022-33317Эксплойта нет | Inclusion of Functionality from Untrusted Control Sphere vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishiconics · genesis64 · CWE-829 | Высокая7,8 | — | 0,3 % | 20 июл. 2022 г. |
31Наблюдать | CVE-2024-9852Эксплойта нет | Malicious Code Execution Vulnerability in GENESIS64, ICONICS Suite, Hyper Historian, MC Works64, and GENESIS32mitsubishi electric corporation · genesis64 · CWE-427 | Высокая7,8 | — | 0,2 % | 28 нояб. 2024 г. |
31Наблюдать | CVE-2024-8299Эксплойта нет | Malicious Code Execution Vulnerability in GENESIS64, ICONICS Suite, Hyper Historian, MC Works64, and GENESIS32mitsubishi electric corporation · genesis64 · CWE-427 | Высокая7,8 | — | 0,2 % | 28 нояб. 2024 г. |
31Наблюдать | CVE-2024-7587Эксплойта нет | Information Disclosure, Information Tampering and Denial of Service (DoS) Vulnerability in GENESIS64, ICONICS Suite, MC Works64, and GENESIS32iconics · genesis64 · CWE-276 | Высокая7,8 | — | 0,2 % | 22 окт. 2024 г. |
30Наблюдать | CVE-2022-29834Эксплойта нет | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mitsubishi Electric GENESIS64 versions 10.97iconics · genesis64 · CWE-22 | Высокая7,5 | — | 1,6 % | 20 июл. 2022 г. |
28Наблюдать | CVE-2022-40264Эксплойта нет | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ICONICS/Mitsubishi Electric GENESIS64 versioiconics · genesis64 · CWE-22 | Высокая7,1 | — | 0,3 % | 13 дек. 2022 г. |
28Наблюдать | CVE-2024-1182Эксплойта нет | Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suitmitsubishi electric iconics digital solutions · genesis64 · CWE-427 | Высокая7,0 | — | 0,3 % | 4 июл. 2024 г. |
- CVE-2022-3331853В плане
Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digi
КритическаяCVSS 9,8Эксплойта нетEPSS 48 %iconics · genesis6420 июл. 2022 г.
- CVE-2011-208948В плане
Stack-based buffer overflow in the SetActiveXGUID method in the VersionInfo ActiveX control in GenVersion.dll 8.0.138.0 in the WebHMI subsys
КритическаяCVSS 9,3Готовый эксплойтEPSS 38 %iconics · bizviz13 мая 2011 г.
- CVE-2020-1201148В плане
A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition or allow remote code executi
КритическаяCVSS 9,8Эксплойта нетEPSS 29 %mitsubishielectric · mc works16 июл. 2020 г.
- CVE-2011-508941В плане
Buffer overflow in the Security Login ActiveX controls in ICONICS GENESIS32 8.05, 9.0, 9.1, and 9.2 and BizViz 8.05, 9.0, 9.1, and 9.2 allow
КритическаяCVSS 10,0Эксплойта нетEPSS 4 %iconics · genesis3218 апр. 2012 г.
- CVE-2020-1200740В плане
A specially crafted communication packet sent to the affected devices could allow remote code execution and a denial-of-service condition du
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %mitsubishielectric · mc works16 июл. 2020 г.
- CVE-2022-2312840В плане
Incomplete List of Disallowed Inputs vulnerability in Mitsubishi Electric MC Works64 versions 4.00A (10.95.201.23) to 4.04E (10.95.210.01),
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %iconics · analytix21 янв. 2022 г.
- CVE-2011-508838Наблюдать
The GENESIS32 IcoSetServer ActiveX control in ICONICS GENESIS32 9.21 and BizViz 9.21 configures the trusted zone on the basis of user input,
КритическаяCVSS 9,3Эксплойта нетEPSS 3 %iconics · bizviz18 апр. 2012 г.
- CVE-2014-075838Наблюдать
ICONICS GENESIS32 Exposed Dangerous Method or Function
КритическаяCVSS 9,3Эксплойта нетEPSS 2 %iconics · genesis3224 февр. 2014 г.
- CVE-2020-1201337Наблюдать
A specially crafted WCF client that interfaces to the may allow the execution of certain arbitrary SQL commands remotely.
КритическаяCVSS 9,1Эксплойта нетEPSS 3 %mitsubishielectric · mc works3216 июл. 2020 г.
- CVE-2022-3331936Наблюдать
Out-of-bounds Read vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions G
КритическаяCVSS 9,1Эксплойта нетEPSS 2 %iconics · genesis6420 июл. 2022 г.
- CVE-2006-648832Наблюдать
Stack-based buffer overflow in the DoModal function in the Dialog Wrapper Module ActiveX control (DlgWrapper.dll) before 8.4.166.0, as used
ВысокаяCVSS 7,5Proof of conceptEPSS 8 %iconics · dialog wrapper module activex control31 дек. 2006 г.
- CVE-2021-2704132Наблюдать
A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files.
ВысокаяCVSS 7,8Эксплойта нетEPSS 2 %autodesk · advance steel25 июн. 2021 г.
- CVE-2020-1200931Наблюдать
A specially crafted communication packet sent to the affected device could cause a denial-of-service condition due to a deserialization vuln
ВысокаяCVSS 7,5Эксплойта нетEPSS 4 %mitsubishielectric · mc works16 июл. 2020 г.
- CVE-2016-228931Наблюдать
Directory traversal vulnerability in ICONICS WebHMI 9 and earlier allows remote attackers to read configuration files, and consequently disc
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %iconics · webhmi1 апр. 2016 г.
- CVE-2020-1201531Наблюдать
A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition due to improper deserializat
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %mitsubishielectric · mc works16 июл. 2020 г.
- CVE-2022-3332031Наблюдать
Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digi
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %iconics · genesis6420 июл. 2022 г.
- CVE-2022-3331631Наблюдать
Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digi
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %iconics · genesis6420 июл. 2022 г.
- CVE-2022-3331531Наблюдать
Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digi
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %iconics · genesis6420 июл. 2022 г.
- CVE-2022-3331731Наблюдать
Inclusion of Functionality from Untrusted Control Sphere vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubish
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %iconics · genesis6420 июл. 2022 г.
- CVE-2024-985231Наблюдать
Malicious Code Execution Vulnerability in GENESIS64, ICONICS Suite, Hyper Historian, MC Works64, and GENESIS32
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %mitsubishi electric corporation · genesis6428 нояб. 2024 г.
- CVE-2024-829931Наблюдать
Malicious Code Execution Vulnerability in GENESIS64, ICONICS Suite, Hyper Historian, MC Works64, and GENESIS32
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %mitsubishi electric corporation · genesis6428 нояб. 2024 г.
- CVE-2024-758731Наблюдать
Information Disclosure, Information Tampering and Denial of Service (DoS) Vulnerability in GENESIS64, ICONICS Suite, MC Works64, and GENESIS32
ВысокаяCVSS 7,8Эксплойта нетEPSS 0 %iconics · genesis6422 окт. 2024 г.
- CVE-2022-2983430Наблюдать
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mitsubishi Electric GENESIS64 versions 10.97
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %iconics · genesis6420 июл. 2022 г.
- CVE-2022-4026428Наблюдать
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ICONICS/Mitsubishi Electric GENESIS64 versio
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %iconics · genesis6413 дек. 2022 г.
- CVE-2024-118228Наблюдать
Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suit
ВысокаяCVSS 7,0Эксплойта нетEPSS 0 %mitsubishi electric iconics digital solutions · genesis644 июл. 2024 г.