CVE-2022-33316

HIGH

Mitsubishi Electric GENESIS64 <10.97.1 - Code Injection

Title source: llm

Description

Deserialization of Untrusted Data vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric ICONICS Suite versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97 to 10.97.1, and Mitsubishi Electric MC Works64 versions 4.04E and prior allows an unauthenticated attacker to execute an arbitrary malicious code by leading a user to load a monitoring screen file including malicious XAML codes.

Scores

CVSS v3 7.8
EPSS 0.0011
EPSS Percentile 29.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Classification

CWE
CWE-502
Status published

Affected Products (3)

iconics/genesis64
iconics/genesis64
mitsubishielectric/mc_works64 < 10.95.210.01

Timeline

Published Jul 20, 2022
Tracked Since Feb 18, 2026