CVE-2022-23127
6.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Exploitability: 2.8 / Impact: 2.7
Source: NVD
Description
Cross-site Scripting vulnerability in Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior and ICONICS MobileHMI versions 10.96.2 and prior allows a remote unauthenticated attacker to gain authentication information of an MC Works64 or MobileHMI and perform any operation using the acquired authentication information, by injecting a malicious script in the URL of a monitoring screen delivered from the MC Works64 server or MobileHMI server to an application for mobile devices and leading a legitimate user to access this URL.
Affected (2)
Products: Iconics: Mobilehmi · Mitsubishielectric: Mc Works64
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 10.96.2 | |
| Before 10.95.210.01 |
References (6)
Source: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
MitigationThird Party AdvisoryVDB Entry
Source: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
MitigationThird Party AdvisoryUS Government ResourceVDB Entry
Source: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
MitigationVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationThird Party AdvisoryUS Government ResourceVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
MitigationVendor Advisory
Timeline
No history available yet.