Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-7587

Опубликовано: 22 окт. 2024
Источник: nvd
CVSS3: 7.8
EPSS Низкий

Описание

Incorrect Default Permissions vulnerability in GenBroker32, which is included in the installers for Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric GENESIS32 versions 9.70.300.23 and prior, Mitsubishi Electric Iconics Digital Solutions GENESIS32 versions 9.70.300.23 and prior, and Mitsubishi Electric MC Works64 all versions allows a local authenticated attacker to disclose or tamper with confidential information and data contained in the products, or cause a denial of service (DoS) condition on the products, by accessing a folder with incorrect permissions, when GenBroker32 is installed on the same PC as GENESIS64, ICONICS Suite, MC Works64, or GENESIS32.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:iconics:genesis64:*:*:*:*:*:*:*:*
Версия до 10.97.3 (включая)
cpe:2.3:a:mitsubishielectric:mc_works64:-:*:*:*:*:*:*:*

EPSS

Процентиль: 37%
0.00162
Низкий

7.8 High

CVSS3

Дефекты

CWE-276

Связанные уязвимости

CVSS3: 7.8
github
больше 1 года назад

Incorrect Default Permissions vulnerability in GenBroker32, which is included in the installers for ICONICS GENESIS64 version 10.97.3 and prior, Mitsubishi Electric GENESIS64 version 10.97.3 and prior and Mitsubishi Electric MC Works64 all versions allows a local authenticated attacker to disclose or tamper with confidential information and data contained in the products, or cause a denial of service (DoS) condition on the products, by accessing a folder with incorrect permissions, when GenBroker32 is installed on the same PC as GENESIS64 or MC Works64.

CVSS3: 7.8
fstec
больше 1 года назад

Уязвимость SCADA-системы GENESIS64 программных пакетов для диспетчерского управления и сбора данных MC Works64, позволяющая нарушителю вызвать отказ в обслуживании или получить доступ к защищаемой информации

EPSS

Процентиль: 37%
0.00162
Низкий

7.8 High

CVSS3

Дефекты

CWE-276