1. EXECUTIVE SUMMARY
- CVSS v4 8.5
- ATTENTION: Low attack complexity
- Vendor: ICONICS, Mitsubishi Electric
- Equipment: ICONICS GENESIS64 Product Suite and Mitsubishi Electric MC Works64
- Vulnerabilities: Uncontrolled Search Path Element, Dead Code
2. RISK EVALUATION
Successful exploitation of these vulnerabilities could result in remote code execution.
3. TECHNICAL DETAILS
3.1 AFFECTED PRODUCTS
ICONICS reports that the following versions of ICONICS and Mitsubishi Electric products are affected:
- GENESIS64 AlarmWorX Multimedia (AlarmWorX64 MMX): Versions prior to 10.97.3 (CVE-2024-8299 and CVE-2024-9852)
- GENESIS64: Version 10.97.2, 10.97.2 CFR1, 10.97.2 CFR2, and 10.97.3 (CVE-2024-8300)
- Mitsubishi Electric MC Works64: all versions (CVE-2024-8299, CVE-2024-9852)
3.2 Vulnerability Overview
3.2.1 Uncontrolled Search Path Element CWE-427
An uncontrolled search path element in the AlarmWorX64 MMX Phone agent can provide the potential for DLL hijacking and malicious code execution.
CVE-2024-8299 has been assigned to this vulnerability. A CVSS v3.1 base score of 7.8 has been calculated; the CVSS vector string is (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
A CVSS v4 score has also been calculated for CVE-2024-8299. A base score of 8.5 has been calculated; the CVSS vector string is (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N).
3.2.2 Uncontrolled Search Path Element CWE-427
An uncontrolled search path element in the AlarmWorX64 MMX Fax agent can provide the potential for DLL hijacking and malicious code execution.
CVE-2024-9852 has been assigned to this vulnerability. A CVSS v3.1 base score of 7.8 has been calculated; the CVSS vector string is (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H).
A CVSS v4 score has also been calculated for CVE-2024-9852. A base score of 8.5 has been calculated; the CVSS vector string is (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N).
3.2.3 Dead Code CWE-561
A dead code issue in the GENESIS64 FA device communications driver can provide the potential for DLL hijacking and malicious code execution.
CVE-2024-8300 has been assigned to this vulnerability. A CVSS v3.1 base score of 7.0 has been calculated; the CVSS vector string is (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
A CVSS v4 score has also been calculated for CVE-2024-8300. A base score of 7.3 has been calculated; the CVSS vector string is (CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N).
3.3 BACKGROUND
- CRITICAL INFRASTRUCTURE SECTORS: Critical Manufacturing
- COUNTRIES/AREAS DEPLOYED: Worldwide
- COMPANY HEADQUARTERS LOCATION: ICONICS is headquartered in the United States. Mitsubishi Electric is headquartered in Japan.
3.4 RESEARCHER
Asher Davila and Malav Vyas of Palo Alto Networks reported these vulnerabilities to ICONICS.
4. MITIGATIONS
For CVE-2024-8299 and CVE-2024-9852, ICONICS Product Suite versions 10.97.3 and later have mitigations for these vulnerabilities. If planning to use the AlarmWorX64 MMX, use the 10.97.3 version and follow the guidelines provided in the ICONICS Whitepaper on Security Vulnerabilities, November 2024 edition.
For CVE-2024-8300, security patches corresponding to each version are as follows:
- If you are using GENESIS64TM version 10.97.2, use version 10.97.2 Critical Fixes Rollup 3.
- If you are using GENESIS64TM version 10.97.3 series, use version 10.97.3 Critical Fixes Rollup 1.
ICONICS and Mitsubishi Electric recommend updating the ICONICS Suite with the latest security patches as they become available. ICONICS Suite security patches may be found here (login required).
ICONICS and Mitsubishi Electric is releasing security updates as critical fixes/rollup releases. Refer to the ICONICS Whitepaper on security vulnerabilities, the most recent version of which can be found here and to the Mitsubishi Electric security advisory for information on the availability of the security updates. MC Works64 users should take the mitigations described in the Mitsubishi Electric security advisory, since there are no plans to release a fix version.
CISA recommends users take defensive measures to minimize the risk of exploitation of these vulnerabilities. CISA reminds organizations to perform proper impact analysis and risk assessment prior to deploying defensive measures.
CISA also provides a section for control systems security recommended practices on the ICS webpage on cisa.gov/ics. Several CISA products detailing cyber defense best practices are available for reading and download, including Improving Industrial Control Systems Cybersecurity with Defense-in-Depth Strategies.
CISA encourages organizations to implement recommended cybersecurity strategies for proactive defense of ICS assets.
Additional mitigation guidance and recommended practices are publicly available on the ICS webpage at cisa.gov/ics in the technical information paper, ICS-TIP-12-146-01B–Targeted Cyber Intrusion Detection and Mitigation Strategies.
Organizations observing suspected malicious activity should follow established internal procedures and report findings to CISA for tracking and correlation against other incidents.
CISA also recommends users take the following measures to protect themselves from social engineering attacks:
No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time. These vulnerabilities are not exploitable remotely.
5. UPDATE HISTORY
- December 3, 2024: Initial Publication