CVE-2020-12013: Iconics Bizviz

Critical severity, CVSS 9.1. EPSS: 3% chance of exploitation in the next 30 days.

A specially crafted WCF client that interfaces to the may allow the execution of certain arbitrary SQL commands remotely. This affects: Mitsubishi Electric MC Works64 Version 4.02C (10.95.208.31) and earlier, all versions; Mitsubishi Electric MC Works32 Version 3.00A (9.50.255.02); ICONICS GenBroker64, Platform Services, Workbench, FrameWorX Server v10.96 and prior; ICONICS GenBroker32 v9.5 and prior.

Affected products

  • Iconics Bizviz: affected versions not specified
  • Iconics Energy Analytix: affected versions not specified
  • Iconics Facility Analytix: affected versions not specified
  • Iconics GENESIS32: affected versions not specified
  • Iconics GENESIS64: affected versions not specified
  • Iconics Hyper Historian: affected versions not specified
  • Iconics Mobilehmi: affected versions not specified
  • Iconics Quality Analytix: affected versions not specified
  • Iconics Smart Energy Analytix: affected versions not specified
  • Mitsubishielectric Mc WORKS32: version 9.50.255.02 only
  • Mitsubishielectric Mc WORKS64: up to and including 10.95.208.31

Published 2020-07-16. Last modified 2026-06-17.