ICONICS kayıtları
iconics üreticisine ait 33 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 1 · %3
- Pre-auth RCE
- 8
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-502 Deserialization of Untrusted Data7
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')3
- CWE-427 Uncontrolled Search Path Element3
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer2
- CWE-125 Out-of-bounds Read2
- CWE-787 Out-of-bounds Write2
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
33 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
53Planlayın | CVE-2022-33318İstismar yok | Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digiiconics · genesis64 · CWE-502 | Kritik9,8 | — | %48,1 | 20 Tem 2022 |
48Planlayın | CVE-2011-2089Silahlaştırılmış | Stack-based buffer overflow in the SetActiveXGUID method in the VersionInfo ActiveX control in GenVersion.dll 8.0.138.0 in the WebHMI subsysiconics · bizviz · CWE-119 | Kritik9,3 | — | %38,3 | 13 May 2011 |
48Planlayın | CVE-2020-12011İstismar yok | A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition or allow remote code executimitsubishielectric · mc works · CWE-787 | Kritik9,8 | — | %29,2 | 16 Tem 2020 |
41Planlayın | CVE-2011-5089İstismar yok | Buffer overflow in the Security Login ActiveX controls in ICONICS GENESIS32 8.05, 9.0, 9.1, and 9.2 and BizViz 8.05, 9.0, 9.1, and 9.2 allowiconics · genesis32 · CWE-119 | Kritik10,0 | — | %4,3 | 18 Nis 2012 |
40Planlayın | CVE-2020-12007İstismar yok | A specially crafted communication packet sent to the affected devices could allow remote code execution and a denial-of-service condition dumitsubishielectric · mc works · CWE-502 | Kritik9,8 | — | %3,9 | 16 Tem 2020 |
40Planlayın | CVE-2022-23128İstismar yok | Incomplete List of Disallowed Inputs vulnerability in Mitsubishi Electric MC Works64 versions 4.00A (10.95.201.23) to 4.04E (10.95.210.01), iconics · analytix | Kritik9,8 | — | %2,9 | 21 Oca 2022 |
38İzleyin | CVE-2011-5088İstismar yok | The GENESIS32 IcoSetServer ActiveX control in ICONICS GENESIS32 9.21 and BizViz 9.21 configures the trusted zone on the basis of user input,iconics · bizviz | Kritik9,3 | — | %2,7 | 18 Nis 2012 |
38İzleyin | CVE-2014-0758İstismar yok | ICONICS GENESIS32 Exposed Dangerous Method or Functioniconics · genesis32 · CWE-749 | Kritik9,3 | — | %1,9 | 24 Şub 2014 |
37İzleyin | CVE-2020-12013İstismar yok | A specially crafted WCF client that interfaces to the may allow the execution of certain arbitrary SQL commands remotely.mitsubishielectric · mc works32 · CWE-94 | Kritik9,1 | — | %3,0 | 16 Tem 2020 |
36İzleyin | CVE-2022-33319İstismar yok | Out-of-bounds Read vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions Giconics · genesis64 · CWE-125 | Kritik9,1 | — | %1,6 | 20 Tem 2022 |
32İzleyin | CVE-2006-6488Kavram kanıtı | Stack-based buffer overflow in the DoModal function in the Dialog Wrapper Module ActiveX control (DlgWrapper.dll) before 8.4.166.0, as used iconics · dialog wrapper module activex control | Yüksek7,5 | — | %7,8 | 31 Ara 2006 |
32İzleyin | CVE-2021-27041İstismar yok | A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files.autodesk · advance steel · CWE-787 | Yüksek7,8 | — | %1,7 | 25 Haz 2021 |
31İzleyin | CVE-2020-12009İstismar yok | A specially crafted communication packet sent to the affected device could cause a denial-of-service condition due to a deserialization vulnmitsubishielectric · mc works · CWE-502 | Yüksek7,5 | — | %3,6 | 16 Tem 2020 |
31İzleyin | CVE-2016-2289İstismar yok | Directory traversal vulnerability in ICONICS WebHMI 9 and earlier allows remote attackers to read configuration files, and consequently disciconics · webhmi · CWE-22 | Yüksek7,5 | — | %2,4 | 1 Nis 2016 |
31İzleyin | CVE-2020-12015İstismar yok | A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition due to improper deserializatmitsubishielectric · mc works · CWE-502 | Yüksek7,5 | — | %2,0 | 16 Tem 2020 |
31İzleyin | CVE-2022-33320İstismar yok | Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digiiconics · genesis64 · CWE-502 | Yüksek7,8 | — | %0,5 | 20 Tem 2022 |
31İzleyin | CVE-2022-33316İstismar yok | Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digiiconics · genesis64 · CWE-502 | Yüksek7,8 | — | %0,3 | 20 Tem 2022 |
31İzleyin | CVE-2022-33315İstismar yok | Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digiiconics · genesis64 · CWE-502 | Yüksek7,8 | — | %0,3 | 20 Tem 2022 |
31İzleyin | CVE-2022-33317İstismar yok | Inclusion of Functionality from Untrusted Control Sphere vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishiconics · genesis64 · CWE-829 | Yüksek7,8 | — | %0,3 | 20 Tem 2022 |
31İzleyin | CVE-2024-9852İstismar yok | Malicious Code Execution Vulnerability in GENESIS64, ICONICS Suite, Hyper Historian, MC Works64, and GENESIS32mitsubishi electric corporation · genesis64 · CWE-427 | Yüksek7,8 | — | %0,2 | 28 Kas 2024 |
31İzleyin | CVE-2024-8299İstismar yok | Malicious Code Execution Vulnerability in GENESIS64, ICONICS Suite, Hyper Historian, MC Works64, and GENESIS32mitsubishi electric corporation · genesis64 · CWE-427 | Yüksek7,8 | — | %0,2 | 28 Kas 2024 |
31İzleyin | CVE-2024-7587İstismar yok | Information Disclosure, Information Tampering and Denial of Service (DoS) Vulnerability in GENESIS64, ICONICS Suite, MC Works64, and GENESIS32iconics · genesis64 · CWE-276 | Yüksek7,8 | — | %0,2 | 22 Eki 2024 |
30İzleyin | CVE-2022-29834İstismar yok | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mitsubishi Electric GENESIS64 versions 10.97iconics · genesis64 · CWE-22 | Yüksek7,5 | — | %1,6 | 20 Tem 2022 |
28İzleyin | CVE-2022-40264İstismar yok | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ICONICS/Mitsubishi Electric GENESIS64 versioiconics · genesis64 · CWE-22 | Yüksek7,1 | — | %0,3 | 13 Ara 2022 |
28İzleyin | CVE-2024-1182İstismar yok | Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suitmitsubishi electric iconics digital solutions · genesis64 · CWE-427 | Yüksek7,0 | — | %0,3 | 4 Tem 2024 |
- CVE-2022-3331853Planlayın
Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digi
KritikCVSS 9,8İstismar yokEPSS %48iconics · genesis6420 Tem 2022
- CVE-2011-208948Planlayın
Stack-based buffer overflow in the SetActiveXGUID method in the VersionInfo ActiveX control in GenVersion.dll 8.0.138.0 in the WebHMI subsys
KritikCVSS 9,3SilahlaştırılmışEPSS %38iconics · bizviz13 May 2011
- CVE-2020-1201148Planlayın
A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition or allow remote code executi
KritikCVSS 9,8İstismar yokEPSS %29mitsubishielectric · mc works16 Tem 2020
- CVE-2011-508941Planlayın
Buffer overflow in the Security Login ActiveX controls in ICONICS GENESIS32 8.05, 9.0, 9.1, and 9.2 and BizViz 8.05, 9.0, 9.1, and 9.2 allow
KritikCVSS 10,0İstismar yokEPSS %4iconics · genesis3218 Nis 2012
- CVE-2020-1200740Planlayın
A specially crafted communication packet sent to the affected devices could allow remote code execution and a denial-of-service condition du
KritikCVSS 9,8İstismar yokEPSS %4mitsubishielectric · mc works16 Tem 2020
- CVE-2022-2312840Planlayın
Incomplete List of Disallowed Inputs vulnerability in Mitsubishi Electric MC Works64 versions 4.00A (10.95.201.23) to 4.04E (10.95.210.01),
KritikCVSS 9,8İstismar yokEPSS %3iconics · analytix21 Oca 2022
- CVE-2011-508838İzleyin
The GENESIS32 IcoSetServer ActiveX control in ICONICS GENESIS32 9.21 and BizViz 9.21 configures the trusted zone on the basis of user input,
KritikCVSS 9,3İstismar yokEPSS %3iconics · bizviz18 Nis 2012
- CVE-2014-075838İzleyin
ICONICS GENESIS32 Exposed Dangerous Method or Function
KritikCVSS 9,3İstismar yokEPSS %2iconics · genesis3224 Şub 2014
- CVE-2020-1201337İzleyin
A specially crafted WCF client that interfaces to the may allow the execution of certain arbitrary SQL commands remotely.
KritikCVSS 9,1İstismar yokEPSS %3mitsubishielectric · mc works3216 Tem 2020
- CVE-2022-3331936İzleyin
Out-of-bounds Read vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions G
KritikCVSS 9,1İstismar yokEPSS %2iconics · genesis6420 Tem 2022
- CVE-2006-648832İzleyin
Stack-based buffer overflow in the DoModal function in the Dialog Wrapper Module ActiveX control (DlgWrapper.dll) before 8.4.166.0, as used
YüksekCVSS 7,5Kavram kanıtıEPSS %8iconics · dialog wrapper module activex control31 Ara 2006
- CVE-2021-2704132İzleyin
A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files.
YüksekCVSS 7,8İstismar yokEPSS %2autodesk · advance steel25 Haz 2021
- CVE-2020-1200931İzleyin
A specially crafted communication packet sent to the affected device could cause a denial-of-service condition due to a deserialization vuln
YüksekCVSS 7,5İstismar yokEPSS %4mitsubishielectric · mc works16 Tem 2020
- CVE-2016-228931İzleyin
Directory traversal vulnerability in ICONICS WebHMI 9 and earlier allows remote attackers to read configuration files, and consequently disc
YüksekCVSS 7,5İstismar yokEPSS %2iconics · webhmi1 Nis 2016
- CVE-2020-1201531İzleyin
A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition due to improper deserializat
YüksekCVSS 7,5İstismar yokEPSS %2mitsubishielectric · mc works16 Tem 2020
- CVE-2022-3332031İzleyin
Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digi
YüksekCVSS 7,8İstismar yokEPSS %0iconics · genesis6420 Tem 2022
- CVE-2022-3331631İzleyin
Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digi
YüksekCVSS 7,8İstismar yokEPSS %0iconics · genesis6420 Tem 2022
- CVE-2022-3331531İzleyin
Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digi
YüksekCVSS 7,8İstismar yokEPSS %0iconics · genesis6420 Tem 2022
- CVE-2022-3331731İzleyin
Inclusion of Functionality from Untrusted Control Sphere vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubish
YüksekCVSS 7,8İstismar yokEPSS %0iconics · genesis6420 Tem 2022
- CVE-2024-985231İzleyin
Malicious Code Execution Vulnerability in GENESIS64, ICONICS Suite, Hyper Historian, MC Works64, and GENESIS32
YüksekCVSS 7,8İstismar yokEPSS %0mitsubishi electric corporation · genesis6428 Kas 2024
- CVE-2024-829931İzleyin
Malicious Code Execution Vulnerability in GENESIS64, ICONICS Suite, Hyper Historian, MC Works64, and GENESIS32
YüksekCVSS 7,8İstismar yokEPSS %0mitsubishi electric corporation · genesis6428 Kas 2024
- CVE-2024-758731İzleyin
Information Disclosure, Information Tampering and Denial of Service (DoS) Vulnerability in GENESIS64, ICONICS Suite, MC Works64, and GENESIS32
YüksekCVSS 7,8İstismar yokEPSS %0iconics · genesis6422 Eki 2024
- CVE-2022-2983430İzleyin
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mitsubishi Electric GENESIS64 versions 10.97
YüksekCVSS 7,5İstismar yokEPSS %2iconics · genesis6420 Tem 2022
- CVE-2022-4026428İzleyin
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ICONICS/Mitsubishi Electric GENESIS64 versio
YüksekCVSS 7,1İstismar yokEPSS %0iconics · genesis6413 Ara 2022
- CVE-2024-118228İzleyin
Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suit
YüksekCVSS 7,0İstismar yokEPSS %0mitsubishi electric iconics digital solutions · genesis644 Tem 2024