CVE-2024-8300: Malicious Code Execution Vulnerability in GENESIS64

7.0 CVSS

Description

Dead Code vulnerability in ICONICS GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3 and Mitsubishi Electric GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3 allows a local authenticated attacker to execute a malicious code by tampering with a specially crafted DLL. This could lead to disclose, tamper with, destroy, or delete information in the affected products, or cause a denial of service (DoS) condition on the products.

Classification

CVE ID: CVE-2024-8300

CVSS Base Severity: HIGH

CVSS Base Score: 7.0

Affected Products

Vendor: Mitsubishi Electric Corporation

Product: GENESIS64

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.05% (probability of being exploited)

EPSS Percentile: 17.81% (scored less or equal to compared to others)

EPSS Date: 2025-02-03 (when was this score calculated)

References

https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2024-010_en.pdf
https://jvn.jp/vu/JVNVU93891820

Timeline