PT-2022-21768 · Mitsubishi+1 · Mitsubishi Electric Mc Works64+1

Published

2022-07-20

·

Updated

2026-01-09

·

CVE-2022-33320

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ICONICS GENESIS64 versions 10.97.1 and prior Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior
Description The issue allows an unauthenticated attacker to execute arbitrary malicious code by leading a user to load a project configuration file that includes malicious XML codes. This is due to a Deserialization of Untrusted Data vulnerability.
Recommendations For ICONICS GENESIS64 versions 10.97.1 and prior, consider disabling the loading of project configuration files from untrusted sources until a patch is available. For Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior, restrict access to the project configuration file loading functionality to minimize the risk of exploitation. As a temporary workaround, avoid using the project configuration file feature in the affected software until the issue is resolved.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2022-33320
ZDI-22-1163
ZDI-23-343

Affected Products

Iconics Genesis64
Mitsubishi Electric Mc Works64