CVE-2020-12013
A specially crafted WCF client that interfaces to the may allow the execution of certain arbitrary SQL commands remotely.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.03%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A specially crafted WCF client that interfaces to the may allow the execution of certain arbitrary SQL commands remotely. This affects: Mitsubishi Electric MC Works64 Version 4.02C (10.95.208.31) and earlier, all versions; Mitsubishi Electric MC Works32 Version 3.00A (9.50.255.02); ICONICS GenBroker64, Platform Services, Workbench, FrameWorX Server v10.96 and prior; ICONICS GenBroker32 v9.5 and prior.
- CVSS 3.1
- 9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
- EPSS
- 3.03% probability · 87th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-94, CWE-89
- Affected
- mitsubishielectric/mc works32 · mitsubishielectric/mc works64 · iconics/energy analytix · iconics/facility analytix · iconics/genesis64 · iconics/hyper historian · iconics/mobilehmi · iconics/quality analytix · iconics/smart energy analytix · iconics/bizviz · iconics/genesis32
- Source
- ics-cert@hq.dhs.gov
References
- https://us-cert.cisa.gov/ics/advisories/icsa-20-170-02Third Party Advisory, US Government Resource
- https://us-cert.cisa.gov/ics/advisories/icsa-20-170-03Third Party Advisory, US Government Resource
- https://us-cert.cisa.gov/ics/advisories/icsa-20-170-02Third Party Advisory, US Government Resource
- https://us-cert.cisa.gov/ics/advisories/icsa-20-170-03Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.