VUMETRIC CYBER PORTAL
  • Dashboard
  • Security News
  • Latest Vulnerabilities
  • Browse Vulnerabilities
    • by Vendors
    • by Products
    • by Categories
  • Weekly Reports

Vulnerabilities > Iconics > Analytix

DATE CVE VULNERABILITY TITLE RISK
2022-01-21 CVE-2022-23128 Incomplete List of Disallowed Inputs vulnerability in Mitsubishi Electric MC Works64 versions 4.00A (10.95.201.23) to 4.04E (10.95.210.01), ICONICS GENESIS64 versions 10.95.3 to 10.97, ICONICS Hyper Historian versions 10.95.3 to 10.97, ICONICS AnalytiX versions 10.95.3 to 10.97 and ICONICS MobileHMI versions 10.95.3 to 10.97 allows a remote unauthenticated attacker to bypass the authentication of MC Works64, GENESIS64, Hyper Historian, AnalytiX and MobileHMI, and gain unauthorized access to the products, by sending specially crafted WebSocket packets to FrameWorX server, one of the functions of the products.
network
low complexity
mitsubishielectric iconics
critical
9.8
9.8

© 2025 Vumetric Inc. All Rights Reserved.
  • About |
  • FAQ |
  • Privacy Policy |
  • Vumetric Public Website

CVE is a registered MITRE Corporation trademark and MITRE's CVE website is the authoritative source of CVE content. CWE is a registered MITRE Corporation trademark and MITRE's CWE website is the authoritative source of CWE content.