CVE-2024-8300: Iconics GENESIS64
High severity, CVSS 7.0. EPSS: 0.2% chance of exploitation in the next 30 days.
Dead Code vulnerability in Mitsubishi Electric GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3, Mitsubishi Electric Iconics Digital Solutions GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3, Mitsubishi Electric ICONICS Suite Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3, and Mitsubishi Electric Iconics Digital Solutions ICONICS Suite Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3 allows a local authenticated attacker to execute a malicious code by tampering with a specially crafted DLL. This could lead to disclose, tamper with, destroy, or delete information in the affected products, or cause a denial of service (DoS) condition on the products.
Affected products
- Iconics GENESIS64: version 10.97.2 only; version 10.97.2cfr1 only; version 10.97.2cfr2 only; version 10.97.3 only
- Mitsubishi Electric Corporation GENESIS64: version 10.97.2 only; version 10.97.2 CFR1 only; version 10.97.2 CRF2 only; version 10.97.3 only
- Mitsubishi Electric Corporation Iconics Suite: version 10.97.2 only; version 10.97.2 CFR1 only; version 10.97.2 CRF2 only; version 10.97.3 only
- Mitsubishi Electric Iconics Digital Solutions GENESIS64: version 10.97.2 only; version 10.97.2 CFR1 only; version 10.97.2 CRF2 only; version 10.97.3 only
- Mitsubishi Electric Iconics Digital Solutions Iconics Suite: version 10.97.2 only; version 10.97.2 CFR1 only; version 10.97.2 CRF2 only; version 10.97.3 only
- Mitsubishielectric GENESIS64: version 10.97.2 only; version 10.97.2cfr1 only; version 10.97.2cfr2 only; version 10.97.3 only
Published 2024-11-28. Last modified 2026-06-17.