#VU65761 Deserialization of Untrusted Data in ICONICS, Inc. products - CVE-2022-33320
Published: July 25, 2022 / Updated: April 3, 2023
GENESIS64
Energy AnalytiX
IoTWorX
GraphWorX64
GenBrokerX64
Hyper Historian
MobileHMI
ICONICS, Inc.
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data. A remote attacker can trick the victim to open a specially crafted PKGX file and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.