Cross-site Scripting vulnerability in Mitsubishi Electric MC Works64 versions 4.04E (10.95.210.01) and prior and ICONICS MobileHMI versions 10.96.2 and prior allows a remote unauthenticated attacker to gain authentication information of an MC Works64 or MobileHMI and perform any operation using the acquired authentication information, by injecting a malicious script in the URL of a monitoring screen delivered from the MC Works64 server or MobileHMI server to an application for mobile devices and leading a legitimate user to access this URL.
References
Link | Resource |
---|---|
https://jvn.jp/vu/JVNVU95403720/index.html | Mitigation Third Party Advisory VDB Entry |
https://www.cisa.gov/uscert/ics/advisories/icsa-22-020-01 | Mitigation Third Party Advisory US Government Resource VDB Entry |
https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2021-025_en.pdf | Mitigation Vendor Advisory |
https://jvn.jp/vu/JVNVU95403720/index.html | Mitigation Third Party Advisory VDB Entry |
https://www.cisa.gov/uscert/ics/advisories/icsa-22-020-01 | Mitigation Third Party Advisory US Government Resource VDB Entry |
https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2021-025_en.pdf | Mitigation Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 06:48
Type | Values Removed | Values Added |
---|---|---|
References | () https://jvn.jp/vu/JVNVU95403720/index.html - Mitigation, Third Party Advisory, VDB Entry | |
References | () https://www.cisa.gov/uscert/ics/advisories/icsa-22-020-01 - Mitigation, Third Party Advisory, US Government Resource, VDB Entry | |
References | () https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2021-025_en.pdf - Mitigation, Vendor Advisory |
27 Jan 2022, 20:03
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-79 | |
CVSS |
v2 : v3 : |
v2 : 4.3
v3 : 6.1 |
CPE | cpe:2.3:a:mitsubishielectric:mc_works64:*:*:*:*:*:*:*:* cpe:2.3:a:iconics:mobilehmi:*:*:*:*:*:*:*:* |
|
References | (MISC) https://www.cisa.gov/uscert/ics/advisories/icsa-22-020-01 - Mitigation, Third Party Advisory, US Government Resource, VDB Entry | |
References | (MISC) https://jvn.jp/vu/JVNVU95403720/index.html - Mitigation, Third Party Advisory, VDB Entry | |
References | (MISC) https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2021-025_en.pdf - Mitigation, Vendor Advisory |
21 Jan 2022, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2022-01-21 19:15
Updated : 2024-11-21 06:48
NVD link : CVE-2022-23127
Mitre link : CVE-2022-23127
CVE.ORG link : CVE-2022-23127
JSON object : View
Products Affected
iconics
- mobilehmi
mitsubishielectric
- mc_works64
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')