PT-2020-4198 · Mitsubishi+1 · Mc Works64+6

Published

2020-06-30

·

Updated

2020-07-29

·

CVE-2020-12009

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Mitsubishi Electric MC Works64 versions 4.02C and earlier Mitsubishi Electric MC Works32 version 3.00A ICONICS GenBroker64 versions prior to 10.96 ICONICS GenBroker32 version 9.5 and prior ICONICS FrameWorX Server versions prior to 10.96 ICONICS Platform Services versions prior to 10.96 ICONICS Workbench versions prior to 10.96
Description: The issue is related to the deserialization vulnerability, which can cause a denial-of-service condition when a specially crafted communication packet is sent to the affected device. This can allow a remote attacker to cause a service disruption. The vulnerability is also associated with the restoration of an invalid data structure in memory.
Recommendations: For Mitsubishi Electric MC Works64 versions 4.02C and earlier, update to a version later than 4.02C to resolve the issue. For Mitsubishi Electric MC Works32 version 3.00A, update to a version later than 3.00A to resolve the issue. For ICONICS GenBroker64 versions prior to 10.96, update to version 10.96 or later to resolve the issue. For ICONICS GenBroker32 version 9.5 and prior, update to a version later than 9.5 to resolve the issue. For ICONICS FrameWorX Server versions prior to 10.96, update to version 10.96 or later to resolve the issue. For ICONICS Platform Services versions prior to 10.96, update to version 10.96 or later to resolve the issue. For ICONICS Workbench versions prior to 10.96, update to version 10.96 or later to resolve the issue.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04632
CVE-2020-12009
ZDI-20-777

Affected Products

Frameworx Server
Genbroker32
Genbroker64
Mc Works32
Mc Works64
Platform Services
Workbench