Vulnerabilities > Iconics > Genesis32 > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-07-16 CVE-2020-12015 Deserialization of Untrusted Data vulnerability in multiple products
A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition due to improper deserialization.
network
low complexity
mitsubishielectric iconics CWE-502
5.0
2020-07-16 CVE-2020-12013 SQL Injection vulnerability in multiple products
A specially crafted WCF client that interfaces to the may allow the execution of certain arbitrary SQL commands remotely.
network
low complexity
mitsubishielectric iconics CWE-89
6.4
2020-07-16 CVE-2020-12009 Deserialization of Untrusted Data vulnerability in multiple products
A specially crafted communication packet sent to the affected device could cause a denial-of-service condition due to a deserialization vulnerability.
network
low complexity
mitsubishielectric iconics CWE-502
5.0
2012-07-31 CVE-2012-3018 Cryptographic Issues vulnerability in Iconics Bizviz and Genesis32
The lockout-recovery feature in the Security Configurator component in ICONICS GENESIS32 9.22 and earlier and BizViz 9.22 and earlier uses an improper encryption algorithm for generation of an authentication code, which allows local users to bypass intended access restrictions and obtain administrative access by predicting a challenge response.
4.4