CVE-2020-12007: Iconics Bizviz
Critical severity, CVSS 9.8. EPSS: 3.9% chance of exploitation in the next 30 days.
A specially crafted communication packet sent to the affected devices could allow remote code execution and a denial-of-service condition due to a deserialization vulnerability. This issue affects: Mitsubishi Electric MC Works64 version 4.02C (10.95.208.31) and earlier, all versions; Mitsubishi Electric MC Works32 version 3.00A (9.50.255.02); ICONICS GenBroker64, Platform Services, Workbench, FrameWorX Server version 10.96 and prior; ICONICS GenBroker32 version 9.5 and prior.
Affected products
- Iconics Bizviz: affected versions not specified
- Iconics Energy Analytix: affected versions not specified
- Iconics Facility Analytix: affected versions not specified
- Iconics GENESIS32: affected versions not specified
- Iconics GENESIS64: affected versions not specified
- Iconics Hyper Historian: affected versions not specified
- Iconics Mobilehmi: affected versions not specified
- Iconics Quality Analytix: affected versions not specified
- Iconics Smart Energy Analytix: affected versions not specified
- Mitsubishielectric Mc Works: up to and including 10.95.208.31
- Mitsubishielectric Mc WORKS32: version 9.50.255.02 only
Published 2020-07-16. Last modified 2026-06-17.