Incorrect Default Permissions vulnerability in GenBroker32, which is included in the installers for ICONICS GENESIS64 version 10.97.3 and prior, Mitsubishi Electric GENESIS64 version 10.97.3 and prior and Mitsubishi Electric MC Works64 all versions allows a local authenticated attacker to disclose or tamper with confidential information and data contained in the products, or cause a denial of service (DoS) condition on the products, by accessing a folder with incorrect permissions, when GenBroker32 is installed on the same PC as GENESIS64 or MC Works64.
History

Wed, 06 Nov 2024 16:15:00 +0000

Type Values Removed Values Added
CPEs cpe:2.3:a:mitsubishielectric:mc_works64:*:*:*:*:*:*:*:*
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 05 Nov 2024 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Iconics
Iconics genesis64
Mitsubishielectric
Mitsubishielectric mc Works64
CPEs cpe:2.3:a:iconics:genesis64:*:*:*:*:*:*:*:*
cpe:2.3:a:mitsubishielectric:mc_works64:-:*:*:*:*:*:*:*
Vendors & Products Iconics
Iconics genesis64
Mitsubishielectric
Mitsubishielectric mc Works64

Tue, 22 Oct 2024 22:30:00 +0000

Type Values Removed Values Added
Description Incorrect Default Permissions vulnerability in GenBroker32, which is included in the installers for ICONICS GENESIS64 version 10.97.3 and prior, Mitsubishi Electric GENESIS64 version 10.97.3 and prior and Mitsubishi Electric MC Works64 all versions allows a local authenticated attacker to disclose or tamper with confidential information and data contained in the products, or cause a denial of service (DoS) condition on the products, by accessing a folder with incorrect permissions, when GenBroker32 is installed on the same PC as GENESIS64 or MC Works64.
Title Information Disclosure, Information Tampering and Denial of Service (DoS) Vulnerability in GENESIS64 and MC Works64
Weaknesses CWE-276
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Mitsubishi

Published: 2024-10-22T22:19:20.646Z

Updated: 2024-11-06T15:50:04.628Z

Reserved: 2024-08-07T08:06:04.877Z

Link: CVE-2024-7587

cve-icon Vulnrichment

Updated: 2024-10-23T14:22:35.386Z

cve-icon NVD

Status : Analyzed

Published: 2024-10-22T23:15:02.367

Modified: 2024-11-05T17:24:52.503

Link: CVE-2024-7587

cve-icon Redhat

No data.