PT-2022-21767 · Iconics+1 · Genesis64+1

CVE-2022-33319

·

Published

2022-07-20

·

Updated

2026-01-09

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions ICONICS GENESIS64 versions 10.97.1 and prior Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior
Description The issue allows a remote unauthenticated attacker to disclose information on memory or cause a Denial of Service (DoS) condition by sending specially crafted packets to the GENESIS64 server.
Recommendations For ICONICS GENESIS64 versions 10.97.1 and prior, update to a version later than 10.97.1 to resolve the issue. For Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior, update to a version later than 4.04E (10.95.210.01) to resolve the issue. As a temporary workaround, consider restricting access to the GENESIS64 server to minimize the risk of exploitation.

Fix

DoS

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-33319
ZDI-22-1044

Affected Products

Genesis64
Mc Works64