CVE-2020-12013
A specially crafted WCF client that interfaces to the may allow the execution of certain arbitrary SQL commands remotely. This affects: Mitsubishi Electric MC Works64 Version 4.02C (10.95.208.31) and earlier, all versions; Mitsubishi Electric MC Works32 Version 3.00A (9.50.255.02); ICONICS GenBroker64, Platform Services, Workbench, FrameWorX Server v10.96 and prior; ICONICS GenBroker32 v9.5 and prior.
Published:Jul 16, 2020
Last Modified:Nov 21, 2024
EPS:Jul 16, 2020
EPSS Score:0.00906
CVSS Score:9.1
Affected Products
Vendor
Product
Action
Vendor
Iconics
Product
Bizviz
Iconics
Bizviz
Vendor
Iconics
Product
Energy Analytix
Iconics
Energy Analytix
Vendor
Iconics
Product
Facility Analytix
Iconics
Facility Analytix
Vendor
Iconics
Product
Genesis32
Iconics
Genesis32
Vendor
Iconics
Product
Genesis64
Iconics
Genesis64
Vendor
Iconics
Product
Hyper Historian
Iconics
Hyper Historian
Vendor
Iconics
Product
Mobilehmi
Iconics
Mobilehmi
Vendor
Iconics
Product
Quality Analytix
Iconics
Quality Analytix
Vendor
Iconics
Product
Smart Energy Analytix
Iconics
Smart Energy Analytix
Vendor
Mitsubishielectric
Product
Mc Works32
Mitsubishielectric
Mc Works32
Vendor
Mitsubishielectric
Product
Mc Works64
Mitsubishielectric
Mc Works64
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
