CVE Database
/

CVE-2022-29834

Back to search

CVE-2022-29834

Published: Jul 20, 2022

Modified: Jan 9, 2026

PUBLISHED

CVSS v3.1

7.5

HIGH

Description

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mitsubishi Electric GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric Iconics Digital Solutions GENESIS64 versions 10.97 to 10.97.1, Mitsubishi Electric ICONICS Suite versions 10.97 to 10.97.1, and Mitsubishi Electric Iconics Digital Solutions ICONICS Suite versions 10.97 to 10.97.1 allows a remote unauthenticated attacker to access to arbitrary files in the GENESIS64 server or ICONICS suite server and disclose information stored in the files by embedding a malicious URL parameter in the URL of the monitoring screen delivered to the GENESIS64 or ICONICS Suite mobile monitoring application and accessing the monitoring screen.

VendorProductVersions

Mitsubishi Electric

GENESIS64

affected
Versions 10.97 to 10.97.1

Mitsubishi Electric Iconics Digital Solutions

GENESIS64

affected
Versions 10.97 to 10.97.1

Mitsubishi Electric

ICONICS Suite

affected
Versions 10.97 to 10.97.1

Mitsubishi Electric Iconics Digital Solutions

ICONICS Suite

affected
Versions 10.97 to 10.97.1

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

None

User Interaction

None

Scope

Unchanged

Confidentiality

High

Integrity

None

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now