CVE-2024-8300
Dead Code vulnerability in Mitsubishi Electric GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3, Mitsubishi Electric Iconics Digital Solutions GENESIS64 Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3, Mitsubishi Electric ICONICS Suite Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3, and Mitsubishi Electric Iconics Digital Solutions ICONICS Suite Version 10.97.2, 10.97.2 CFR1, 10.97.2 CRF2 and 10.97.3 allows a local authenticated attacker to execute a malicious code by tampering with a specially crafted DLL. This could lead to disclose, tamper with, destroy, or delete information in the affected products, or cause a denial of service (DoS) condition on the products.
Scoring
- Severity
- HIGH
- CVSS base score
- 7
- CVSS vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.20%
- CWE
- CWE-561
- Published
- 2024-11-28
- Last modified
- 2026-03-13
Affected products
- Mitsubishi Electric Corporation GENESIS64
- Mitsubishi Electric Corporation GENESIS64
- Mitsubishi Electric Corporation GENESIS64
- Mitsubishi Electric Corporation GENESIS64
- Mitsubishi Electric Iconics Digital Solutions GENESIS64
- Mitsubishi Electric Iconics Digital Solutions GENESIS64
- Mitsubishi Electric Iconics Digital Solutions GENESIS64
- Mitsubishi Electric Iconics Digital Solutions GENESIS64
Weakness type
Related vulnerabilities
- CVE-2026-44057 — Dead bounds check in Spotlight RPC unmarshaller
- CVE-2025-34205 — Vasion Print (formerly PrinterLogic) Dangerous PHP Dead Code Enables RCE
- CVE-2024-32634 — Logically dead code
- CVE-2022-33726 — Unprotected dynamic receiver in Samsung Galaxy Friends prior to SMR Aug-2022 Release 1 allows...
- CVE-2022-33685 — Unprotected dynamic receiver in Wearable Manager Service prior to SMR Jul-2022 Release 1 allows...
- CVE-2022-30748 — Unprotected dynamic receiver in Samsung Members prior to version 4.2.005 allows attacker to launch...
- CVE-2021-25398 — Intent redirection vulnerability in Bixby Voice prior to version 3.1.12 allows attacker to access...
- CVE-2018-0039 — Contrail Service Orchestration: Hardcoded credentials for Grafana service