CVE-2022-40264

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
14/12/2022
Last modified:
16/12/2022

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ICONICS/Mitsubishi Electric GENESIS64 versions 10.96 to 10.97.2 allows an unauthenticated attacker to create, tamper with or destroy arbitrary files by getting a legitimate user import a project package file crafted by the attacker.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:iconics:genesis64:*:*:*:*:*:*:*:* 10.96 (including) 10.97.2 (including)