CVE-2022-40264: Iconics GENESIS64

High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ICONICS/Mitsubishi Electric GENESIS64 versions 10.96 to 10.97.2 allows an unauthenticated attacker to create, tamper with or destroy arbitrary files by getting a legitimate user import a project package file crafted by the attacker.

Affected products

  • Iconics GENESIS64: from 10.96, up to and including 10.97.2

Published 2022-12-14. Last modified 2026-06-17.