PT-2024-7226 · Mitsubishi · Genesis64+1
Asher Davila
+1
·
Published
2024-10-22
·
Updated
2026-01-31
·
CVE-2024-7587
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
ICONICS GENESIS64 versions 10.97.3 and prior
Mitsubishi Electric GENESIS64 versions 10.97.3 and prior
Mitsubishi Electric MC Works64 all versions
Description
The issue is related to incorrect default permissions in GenBroker32, which is included in the installers for the mentioned products. This allows a local authenticated attacker to disclose or tamper with confidential information and data contained in the products, or cause a denial of service (DoS) condition on the products, by accessing a folder with incorrect permissions, when GenBroker32 is installed on the same PC as GENESIS64 or MC Works64.
Recommendations
For ICONICS GENESIS64 versions 10.97.3 and prior, consider disabling the GenBroker32 component until a patch is available.
For Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, restrict access to the folder with incorrect permissions to minimize the risk of exploitation.
For Mitsubishi Electric MC Works64 all versions, avoid using the vulnerable GenBroker32 component until the issue is resolved.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
DoS
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Genesis64
Mc Works64