Medium severity6.3NVD Advisory· Published Dec 14, 2022· Updated Jun 17, 2026
CVE-2022-40264
CVE-2022-40264
Description
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ICONICS/Mitsubishi Electric GENESIS64 versions 10.96 to 10.97.2 allows an unauthenticated attacker to create, tamper with or destroy arbitrary files by getting a legitimate user import a project package file crafted by the attacker.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
4- Range: 10.96 to 10.97.2
- ICONICS and Mitsubishi Electric Corporation/GENESIS64v5Range: versions 10.96 to 10.97.2
Patches
Vulnerability mechanics
References
4- iconics.com/About/Security/CERTnvdVendor Advisory
- jvn.jp/vu/JVNVU95858406/index.htmlnvdThird Party Advisory
- www.cisa.gov/uscert/ics/advisories/icsa-22-347-01nvdThird Party AdvisoryUS Government Resource
- www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-014_en.pdfnvdMitigationVendor Advisory
News mentions
0No linked articles in our index yet.