PT-2020-4199 · Mitsubishi+1 · Mc Works64+6

Published

2020-06-30

·

Updated

2021-11-04

·

CVE-2020-12013

CVSS v3.1

9.4

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Mitsubishi Electric MC Works64 versions 4.02C and earlier Mitsubishi Electric MC Works32 version 3.00A ICONICS GenBroker64 versions 10.96 and prior ICONICS GenBroker32 versions 9.5 and prior ICONICS FrameWorX Server versions 10.96 and prior ICONICS Platform Services versions 10.96 and prior ICONICS Workbench versions 10.96 and prior
Description: The issue allows a specially crafted WCF client to execute arbitrary SQL commands remotely due to insufficient code generation management. This can enable a remote attacker to execute arbitrary commands.
Recommendations: For Mitsubishi Electric MC Works64 versions 4.02C and earlier, update to a version later than 4.02C. For Mitsubishi Electric MC Works32 version 3.00A, update to a version later than 3.00A. For ICONICS GenBroker64 versions 10.96 and prior, update to a version later than 10.96. For ICONICS GenBroker32 versions 9.5 and prior, update to a version later than 9.5. For ICONICS FrameWorX Server versions 10.96 and prior, update to a version later than 10.96. For ICONICS Platform Services versions 10.96 and prior, update to a version later than 10.96. For ICONICS Workbench versions 10.96 and prior, update to a version later than 10.96.

Fix

SQL injection

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04633
CVE-2020-12013
ZDI-20-779

Affected Products

Frameworx Server
Genbroker32
Genbroker64
Mc Works32
Mc Works64
Platform Services
Workbench