CVE-2020-12015
Description
A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition due to improper deserialization. This issue affects: Mitsubishi Electric MC Works64 version 4.02C (10.95.208.31) and earlier, all versions; Mitsubishi Electric MC Works32 version 3.00A (9.50.255.02); ICONICS GenBroker64, Platform Services, Workbench, FrameWorX Server version 10.96 and prior; ICONICS GenBroker32 version 9.5 and prior.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Improper deserialization in Mitsubishi Electric MC Works and ICONICS GENESIS products allows remote attackers to cause a denial-of-service condition via a crafted packet.
Vulnerability
CVE-2020-12015 is a deserialization of untrusted data vulnerability (CWE-502) in Mitsubishi Electric MC Works64 (version 4.02C and earlier) and MC Works32 (version 3.00A), as well as ICONICS GENESIS64 and GENESIS32 products using GenBroker64, Platform Services, Workbench, FrameWorX Server (version 10.96 and prior) and GenBroker32 (version 9.5 and prior) [1][2]. A specially crafted communication packet sent to the affected platform services causes improper deserialization, leading to a denial-of-service condition.
Exploitation
An attacker can exploit this vulnerability remotely over the network without authentication or user interaction [1][2]. The attack complexity is low, meaning no special conditions are required. The attacker sends a maliciously crafted packet to the target system's platform services, triggering the deserialization flaw.
Impact
Successful exploitation results in a denial-of-service condition, affecting the availability of the system. There is no impact on confidentiality or integrity [1][2]. The CVSS v3 base score is 7.5 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H).
Mitigation
Mitsubishi Electric and ICONICS have released advisories through CISA [1][2]. Users should update to the latest versions as specified by the vendors. For Mitsubishi Electric MC Works64, upgrade to version 4.02C or later; for MC Works32, upgrade to version 3.00A or later. For ICONICS products, upgrade to versions beyond 10.96 for GENESIS64 and beyond 9.5 for GENESIS32. If patching is not possible, restrict network access to the affected services and apply firewall rules to limit exposure.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
9- Range: <= 10.96
<= 10.96+ 1 more
- (no CPE)range: <= 10.96
- (no CPE)range: version 9.5 and prior
- Range: <= 10.96
- Range: <= 10.96
- Range: <= 4.02C (10.95.208.31)
- ICONICS/GenBroker64, Platform Services, Workbench, FrameWorX Serverv5Range: version 10.96 and prior
- Mitsubishi Electric/MC Works32v5Range: version 3.00A (9.50.255.02)
- Mitsubishi Electric/MC Works64v5Range: version 4.02C (10.95.208.31) and earlier
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.us-cert.gov/ics/advisories/icsa-20-170-02mitrex_refsource_CONFIRM
- www.us-cert.gov/ics/advisories/icsa-20-170-03mitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.