๐Ÿ” CVE Alert

CVE-2024-8299

HIGH 7.8

Malicious Code Execution Vulnerability in GENESIS64, ICONICS Suite, Hyper Historian, MC Works64, and GENESIS32

CVSS Score
7.8
EPSS Score
0.0%
EPSS Percentile
7th

Uncontrolled Search Path Element vulnerability in Mitsubishi Electric GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric Hyper Historian versions 10.97.3 and prior, Mitsubishi Electric GENESIS32 all versions, Mitsubishi Electric MC Works64 all versions, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97.3 and prior, Mitsubishi Electric Iconics Digital Solutions Hyper Historian versions 10.97.3 and prior, and Mitsubishi Electric Iconics Digital Solutions GENESIS32 all versions allows a local authenticated attacker to execute a malicious code by storing a specially crafted DLL in a specific folder. This could lead to disclose, tamper with, destroy, or delete information in the affected products, or to cause a denial of service (DoS) condition on the products.

CWE CWE-427
Vendor mitsubishi electric corporation
Product genesis64
Published Nov 28, 2024
Last Updated Apr 8, 2026
Stay Ahead of the Next One

Get instant alerts for mitsubishi electric corporation genesis64

Be the first to know when new high vulnerabilities affecting mitsubishi electric corporation genesis64 are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

Mitsubishi Electric Corporation / GENESIS64
versions 10.97.3 and prior
Mitsubishi Electric Corporation / ICONICS Suite
versions 10.97.3 and prior
Mitsubishi Electric Corporation / Hyper Historian
versions 10.97.3 and prior
Mitsubishi Electric Corporation / GENESIS32
all versions
Mitsubishi Electric Corporation / MC Works64
all versions
Mitsubishi Electric Iconics Digital Solutions / GENESIS64
versions 10.97.3 and prior
Mitsubishi Electric Iconics Digital Solutions / ICONICS Suite
versions 10.97.3 and prior
Mitsubishi Electric Iconics Digital Solutions / Hyper Historian
versions 10.97.3 and prior
Mitsubishi Electric Iconics Digital Solutions / GENESIS32
all versions

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
mitsubishielectric.com: https://www.mitsubishielectric.com/psirt/vulnerability/pdf/2024-010_en.pdf jvn.jp: https://jvn.jp/vu/JVNVU93891820 cisa.gov: https://www.cisa.gov/news-events/ics-advisories/icsa-24-338-04

Credits

Asher Davila of Palo Alto Networks Malav Vyas of Palo Alto Networks