Skip to main content

Vendor archive

iconics CVEs

Beta · best-effort

27 CVEs tagged to vendor iconics9 Critical, 12 High, 5 Medium, 1 Low, 0 Unrated.

CVE-2024-7587

Published Oct 22, 2024

Incorrect Default Permissions vulnerability in GenBroker32, which is included in the installers for Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric I…

CVSS 7.8 · High
evidence mentions
3
Buzz score
23.9
Vendor/product tagsBeta · best-effort

CVE-2022-40264

Published Dec 14, 2022

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ICONICS/Mitsubishi Electric GENESIS64 versions 10.96 to 10.97.2 allows an unauthent…

CVSS 6.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-29834

Published Jul 20, 2022

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconic…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2021-27041

Published Jun 25, 2021

A maliciously crafted DWG file can be used to write beyond the allocated buffer while parsing DWG files. This vulnerability can be exploited to execute arbitrary code

CVSS 7.8 · High

CVE-2021-27040

Published Jun 25, 2021

A maliciously crafted DWG file can be forced to read beyond allocated boundaries when parsing the DWG file. This vulnerability can be exploited to execute arbitrary code.

CVSS 3.3 · Low

CVE-2020-12015

Published Jul 16, 2020

A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition due to improper deserialization. This issue affects: Mitsubishi Ele…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9

CVE-2020-12013

Published Jul 16, 2020

A specially crafted WCF client that interfaces to the may allow the execution of certain arbitrary SQL commands remotely. This affects: Mitsubishi Electric MC Works64 Version 4.02…

CVSS 9.1 · Critical

CVE-2020-12007

Published Jul 16, 2020

A specially crafted communication packet sent to the affected devices could allow remote code execution and a denial-of-service condition due to a deserialization vulnerability. T…

CVSS 9.8 · Critical

CVE-2020-12009

Published Jul 16, 2020

A specially crafted communication packet sent to the affected device could cause a denial-of-service condition due to a deserialization vulnerability. This affects: Mitsubishi Ele…

CVSS 7.5 · High

CVE-2020-12011

Published Jul 16, 2020

A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition or allow remote code execution. This issue affects: Mitsubishi Elec…

CVSS 9.8 · Critical

CVE-2016-2289

Published Apr 1, 2016

Directory traversal vulnerability in ICONICS WebHMI 9 and earlier allows remote attackers to read configuration files, and consequently discover password hashes, via unspecified v…

CVSS 7.5 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2014-0758

Published Feb 24, 2014

An ActiveX control in GenLaunch.htm in ICONICS GENESIS32 8.0, 8.02, 8.04, and 8.05 allows remote attackers to execute arbitrary programs via a crafted HTML document.

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-3018

Published Jul 31, 2012

The lockout-recovery feature in the Security Configurator component in ICONICS GENESIS32 9.22 and earlier and BizViz 9.22 and earlier uses an improper encryption algorithm for gen…

CVSS 4.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2011-5089

Published Apr 18, 2012

Buffer overflow in the Security Login ActiveX controls in ICONICS GENESIS32 8.05, 9.0, 9.1, and 9.2 and BizViz 8.05, 9.0, 9.1, and 9.2 allows remote attackers to cause a denial of…

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2011-5088

Published Apr 18, 2012

The GENESIS32 IcoSetServer ActiveX control in ICONICS GENESIS32 9.21 and BizViz 9.21 configures the trusted zone on the basis of user input, which allows remote attackers to execu…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 1-25 of 27 CVEsPage 1 of 2