Out-of-bounds read in ICONICS, Inc. products - CVE-2022-23130
Published: January 21, 2022
Vulnerability identifier: #VU59904
CSH Severity: Low
CVSS v4: 4.3 [CVSS:4.0/AV:A/AC:L/AT:P/PR:H/UI:A/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-23130
CWE-ID: CWE-125
Exploitation vector: Adjecent network
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary condition in the SQL query engine. A remote administrator on the local network can trigger out-of-bounds read error and cause a denial of service condition on the system.
Affected software
ICONICS Suite
GENESIS64
Energy AnalytiX
MC Works64
Hyper Historian
MobileHMI
GENESIS64
Energy AnalytiX
MC Works64
Hyper Historian
MobileHMI
How to mitigate CVE-2022-23130
Install updates from vendor's website.
GENESIS64 - update to 10.97.1