PT-2020-4198 · Mitsubishi+1 · Mc Works64+6
Published
2020-06-30
·
Updated
2020-07-29
·
CVE-2020-12009
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions:
Mitsubishi Electric MC Works64 versions 4.02C and earlier
Mitsubishi Electric MC Works32 version 3.00A
ICONICS GenBroker64 versions prior to 10.96
ICONICS GenBroker32 version 9.5 and prior
ICONICS FrameWorX Server versions prior to 10.96
ICONICS Platform Services versions prior to 10.96
ICONICS Workbench versions prior to 10.96
Description:
The issue is related to the deserialization vulnerability, which can cause a denial-of-service condition when a specially crafted communication packet is sent to the affected device. This can allow a remote attacker to cause a service disruption. The vulnerability is also associated with the restoration of an invalid data structure in memory.
Recommendations:
For Mitsubishi Electric MC Works64 versions 4.02C and earlier, update to a version later than 4.02C to resolve the issue.
For Mitsubishi Electric MC Works32 version 3.00A, update to a version later than 3.00A to resolve the issue.
For ICONICS GenBroker64 versions prior to 10.96, update to version 10.96 or later to resolve the issue.
For ICONICS GenBroker32 version 9.5 and prior, update to a version later than 9.5 to resolve the issue.
For ICONICS FrameWorX Server versions prior to 10.96, update to version 10.96 or later to resolve the issue.
For ICONICS Platform Services versions prior to 10.96, update to version 10.96 or later to resolve the issue.
For ICONICS Workbench versions prior to 10.96, update to version 10.96 or later to resolve the issue.
Fix
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Frameworx Server
Genbroker32
Genbroker64
Mc Works32
Mc Works64
Platform Services
Workbench