CVE-2024-1574 Vulnerability Details

  /     /     /  

CVE-2024-1574 Metadata Quick Info

CVE Published: 04/07/2024 | CVE Updated: 01/08/2024 | CVE Year: 2024
Source: Mitsubishi | Vendor: ICONICS | Product: GENESIS64
Status : PUBLISHED

CVE-2024-1574 Description

Use of Externally-Controlled Input to Select Classes or Code (\'Unsafe Reflection\') vulnerability in the licensing feature of ICONICS GENESIS64 versions 10.97 to 10.97.2, Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.2 and Mitsubishi Electric MC Works64 all versions allows a local attacker to execute a malicious code with administrative privileges by tampering with a specific file that is not protected by the system.

Metrics

CVSS Version: 3.1 | Base Score: 6.7 MEDIUM
Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

l➤ Exploitability Metrics:
    Attack Vector (AV)* LOCAL
    Attack Complexity (AC)* HIGH
    Privileges Required (PR)* LOW
    User Interaction (UI)* REQUIRED
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* HIGH
    Integrity Impact (I)* HIGH
    Availability Impact (A)* HIGH

Weakness Enumeration (CWE)

CWE-ID: CWE-470
CWE Name: CWE-470 Use of Externally-Controlled Input to Select Classes or Code ( Unsafe Reflection )
Source: ICONICS

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description: Malicious Code Execution


Source: NVD (National Vulnerability Database).