PT-2020-4196 · Mitsubishi+1 · Mitsubishi Electric Mc Works32+6

Published

2020-06-30

·

Updated

2020-07-29

·

CVE-2020-12011

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Mitsubishi Electric MC Works64 version 4.02C (10.95.208.31) and earlier Mitsubishi Electric MC Works32 version 3.00A (9.50.255.02) ICONICS GenBroker64, Platform Services, Workbench, FrameWorX Server version 10.96 and prior ICONICS GenBroker32 version 9.5 and prior
Description: A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition or allow remote code execution. The issue is related to a buffer overflow, which can be exploited by a remote attacker to execute arbitrary code or cause a denial of service.
Recommendations: For Mitsubishi Electric MC Works64 version 4.02C (10.95.208.31) and earlier, update to a version later than 4.02C. For Mitsubishi Electric MC Works32 version 3.00A (9.50.255.02), update to a version later than 3.00A. For ICONICS GenBroker64, Platform Services, Workbench, FrameWorX Server version 10.96 and prior, update to a version later than 10.96. For ICONICS GenBroker32 version 9.5 and prior, update to a version later than 9.5. As a temporary workaround, consider restricting access to the vulnerable components until a patch is available.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04630
CVE-2020-12011
ZDI-20-778

Affected Products

Iconics Frameworx Server
Iconics Genbroker32
Iconics Genbroker64
Iconics Platform Services
Iconics Workbench
Mitsubishi Electric Mc Works32
Mitsubishi Electric Mc Works64