PT-2020-4200 · Mitsubishi+1 · Mitsubishi Electric Mc Works32+6

Ali Abbasi

+8

·

Published

2020-06-30

·

Updated

2020-07-29

·

CVE-2020-12007

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Mitsubishi Electric MC Works64 version 4.02C (10.95.208.31) and earlier Mitsubishi Electric MC Works32 version 3.00A (9.50.255.02) ICONICS GenBroker64, Platform Services, Workbench, FrameWorX Server version 10.96 and prior ICONICS GenBroker32 version 9.5 and prior
Description: A deserialization vulnerability exists, allowing remote code execution and a denial-of-service condition due to a specially crafted communication packet sent to the affected devices. This issue is related to the restoration of an untrusted data structure in memory, which can be exploited by a remote attacker to execute arbitrary code or cause a denial-of-service.
Recommendations: For Mitsubishi Electric MC Works64 version 4.02C (10.95.208.31) and earlier, update to a version later than 4.02C (10.95.208.31) to resolve the issue. For Mitsubishi Electric MC Works32 version 3.00A (9.50.255.02), update to a version later than 3.00A (9.50.255.02) to resolve the issue. For ICONICS GenBroker64, Platform Services, Workbench, FrameWorX Server version 10.96 and prior, update to a version later than 10.96 to resolve the issue. For ICONICS GenBroker32 version 9.5 and prior, update to a version later than 9.5 to resolve the issue. As a temporary workaround, consider restricting access to the deserialization functionality until a patch is available.

Fix

Deserialization of Untrusted Data

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-04634
CVE-2020-12007
ZDI-20-776

Affected Products

Iconics Frameworx Server
Iconics Genbroker32
Iconics Genbroker64
Iconics Platform Services
Iconics Workbench
Mitsubishi Electric Mc Works32
Mitsubishi Electric Mc Works64