PT-2022-6505 · Mitsubishi+1 · Mitsubishi Electric Mc Works64+1

Published

2022-07-20

·

Updated

2026-01-09

·

CVE-2022-33315

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions ICONICS GENESIS64 versions 10.97.1 and prior Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior
Description The issue is related to the deserialization of untrusted data, which can be exploited by an unauthenticated attacker to execute arbitrary malicious code. This can be achieved by leading a user to load a monitoring screen file that includes malicious XAML codes. The vulnerability is associated with errors in data deserialization in the affected software packages.
Recommendations For ICONICS GENESIS64 versions 10.97.1 and prior, consider disabling the loading of external XAML files until a patch is available. For Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior, restrict access to the monitoring screen file feature to minimize the risk of exploitation. As a temporary workaround, avoid using the affected software to load any untrusted files or data.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2023-01792
CVE-2022-33315
ZDI-22-1043

Affected Products

Iconics Genesis64
Mitsubishi Electric Mc Works64