CVE-2022-23130
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Buffer Over-read vulnerability in Mitsubishi Electric MC Works64 versions 4.00A (10.95.201.23) to 4.04E (10.95.210.01), ICONICS GENESIS64 versions 10.97 and prior and ICONICS Hyper Historian versions 10.97 and prior allows an attacker to cause a DoS condition in the database server by getting a legitimate user to import a configuration file containing specially crafted stored procedures into GENESIS64 or MC Works64 and execute commands against the database from GENESIS64 or MC Works64.
Una vulnerabilidad de lectura excesiva del búfer en Mitsubishi Electric MC Works64 versiones 4.00A (10.95.201.23) a 4.04E (10.95.210.01), en ICONICS GENESIS64 versiones 10.97 y anteriores, y en ICONICS Hyper Historian versiones 10.97 y anteriores, permite a un atacante causar una condición de denegación de servicio en el servidor de la base de datos al hacer que un usuario legítimo importe un archivo de configuración que contenga procedimientos almacenados especialmente diseñados en GENESIS64 o MC Works64 y ejecute comandos contra la base de datos desde GENESIS64 o MC Works64
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-01-11 CVE Reserved
- 2022-01-21 CVE Published
- 2024-08-03 CVE Updated
- 2025-03-30 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-125: Out-of-bounds Read
CAPEC
References (3)
URL | Tag | Source |
---|---|---|
https://jvn.jp/vu/JVNVU95403720/index.html | Mitigation | |
https://us-cert.cisa.gov/ics/advisories/icsa-22-020-01 | Mitigation |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2021-028_en.pdf | 2022-01-27 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Iconics Search vendor "Iconics" | Genesis64 Search vendor "Iconics" for product "Genesis64" | <= 10.97 Search vendor "Iconics" for product "Genesis64" and version " <= 10.97" | - |
Affected
| ||||||
Iconics Search vendor "Iconics" | Hyper Historian Search vendor "Iconics" for product "Hyper Historian" | <= 10.97 Search vendor "Iconics" for product "Hyper Historian" and version " <= 10.97" | - |
Affected
| ||||||
Mitsubishielectric Search vendor "Mitsubishielectric" | Mc Works64 Search vendor "Mitsubishielectric" for product "Mc Works64" | >= 10.95.201.23 <= 10.95.210.01 Search vendor "Mitsubishielectric" for product "Mc Works64" and version " >= 10.95.201.23 <= 10.95.210.01" | - |
Affected
|