CVE-2020-12009
ICONICS Genesis64 PKGX WbPackAndGoSettings Absolute Path Traversal Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A specially crafted communication packet sent to the affected device could cause a denial-of-service condition due to a deserialization vulnerability. This affects: Mitsubishi Electric MC Works64 Version 4.02C (10.95.208.31) and earlier, all versions; Mitsubishi Electric MC Works32 Version 3.00A (9.50.255.02); ICONICS GenBroker64, Platform Services, Workbench, FrameWorX Server v10.96 and prior; ICONICS GenBroker32 v9.5 and prior.
Un paquete de comunicación especialmente diseñado enviado al dispositivo afectado podría causar una condición de denegación de servicio debido a una vulnerabilidad de deserialización. Esto afecta: Mitsubishi Electric MC Works64 versión 4.02C (10.95.208.31) y anteriores, todas las versiones; Mitsubishi Electric MC Works32 versión 3.00A (9.50.255.02); ICONICS GenBroker64, Platform Services, Workbench, FrameWorX Server versión v10.96 y anteriores; ICONICS GenBroker32 versión v9.5 y anteriores
The vulnerablity allows remote attackers to execute arbitrary code on affected installations of ICONICS Genesis64. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the handling of PKGX files. When parsing the WbPackAndGoSettings element, the process does not properly validate a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of SYSTEM.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-04-21 CVE Reserved
- 2020-06-30 CVE Published
- 2024-09-16 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-502: Deserialization of Untrusted Data
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://us-cert.cisa.gov/ics/advisories/icsa-20-170-02 | Third Party Advisory | |
https://us-cert.cisa.gov/ics/advisories/icsa-20-170-03 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Mitsubishielectric Search vendor "Mitsubishielectric" | Mc Works Search vendor "Mitsubishielectric" for product "Mc Works" | <= 10.95.208.31 Search vendor "Mitsubishielectric" for product "Mc Works" and version " <= 10.95.208.31" | - |
Affected
| ||||||
Mitsubishielectric Search vendor "Mitsubishielectric" | Mc Works32 Search vendor "Mitsubishielectric" for product "Mc Works32" | 9.50.255.02 Search vendor "Mitsubishielectric" for product "Mc Works32" and version "9.50.255.02" | - |
Affected
| ||||||
Iconics Search vendor "Iconics" | Energy Analytix Search vendor "Iconics" for product "Energy Analytix" | - | - |
Affected
| ||||||
Iconics Search vendor "Iconics" | Facility Analytix Search vendor "Iconics" for product "Facility Analytix" | - | - |
Affected
| ||||||
Iconics Search vendor "Iconics" | Genesis64 Search vendor "Iconics" for product "Genesis64" | - | - |
Affected
| ||||||
Iconics Search vendor "Iconics" | Hyper Historian Search vendor "Iconics" for product "Hyper Historian" | - | - |
Affected
| ||||||
Iconics Search vendor "Iconics" | Mobilehmi Search vendor "Iconics" for product "Mobilehmi" | - | - |
Affected
| ||||||
Iconics Search vendor "Iconics" | Quality Analytix Search vendor "Iconics" for product "Quality Analytix" | - | - |
Affected
| ||||||
Iconics Search vendor "Iconics" | Smart Energy Analytix Search vendor "Iconics" for product "Smart Energy Analytix" | - | - |
Affected
| ||||||
Iconics Search vendor "Iconics" | Bizviz Search vendor "Iconics" for product "Bizviz" | - | - |
Affected
| ||||||
Iconics Search vendor "Iconics" | Genesis32 Search vendor "Iconics" for product "Genesis32" | - | - |
Affected
|