2024-12-06 10:02:12 +00:00

68 lines
2.8 KiB
JSON

{
"id": "CVE-2024-9852",
"sourceIdentifier": "Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp",
"published": "2024-11-28T23:15:04.890",
"lastModified": "2024-12-06T06:15:23.200",
"vulnStatus": "Awaiting Analysis",
"cveTags": [],
"descriptions": [
{
"lang": "en",
"value": "Uncontrolled Search Path Element vulnerability in ICONICS GENESIS64 all versions, Mitsubishi Electric GENESIS64 all versions and Mitsubishi Electric MC Works64 all versions allows a local authenticated attacker to execute a malicious code by storing a specially crafted DLL in a specific folder. This could lead to disclose, tamper with, destroy, or delete information in the affected products, or cause a denial of service (DoS) condition on the products."
},
{
"lang": "es",
"value": "La vulnerabilidad de elemento de ruta de b\u00fasqueda no controlada en ICONICS GENESIS64 en todas las versiones, Mitsubishi Electric GENESIS64 en todas las versiones y Mitsubishi Electric MC Works64 en todas las versiones permite que un atacante local autenticado ejecute un c\u00f3digo malicioso almacenando una DLL especialmente manipulada en una carpeta espec\u00edfica. Esto podr\u00eda provocar la divulgaci\u00f3n, manipulaci\u00f3n, destrucci\u00f3n o eliminaci\u00f3n de informaci\u00f3n en los productos afectados, o provocar una condici\u00f3n de denegaci\u00f3n de servicio (DoS) en los productos."
}
],
"metrics": {
"cvssMetricV31": [
{
"source": "Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp",
"type": "Secondary",
"cvssData": {
"version": "3.1",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
"baseScore": 7.8,
"baseSeverity": "HIGH",
"attackVector": "LOCAL",
"attackComplexity": "LOW",
"privilegesRequired": "LOW",
"userInteraction": "NONE",
"scope": "UNCHANGED",
"confidentialityImpact": "HIGH",
"integrityImpact": "HIGH",
"availabilityImpact": "HIGH"
},
"exploitabilityScore": 1.8,
"impactScore": 5.9
}
]
},
"weaknesses": [
{
"source": "Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp",
"type": "Secondary",
"description": [
{
"lang": "en",
"value": "CWE-427"
}
]
}
],
"references": [
{
"url": "https://jvn.jp/vu/JVNVU93891820",
"source": "Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp"
},
{
"url": "https://www.cisa.gov/news-events/ics-advisories/icsa-24-338-04",
"source": "Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp"
},
{
"url": "https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2024-010_en.pdf",
"source": "Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp"
}
]
}