https://www.us-cert.gov/ics/advisories/icsa-20-170-02OUT-OF-BOUNDS WRITE CWE-787
A specially crafted communication packet sent to the affected MC Works64 Broker64 or MC Works32 Broker32 systems could cause a denial-of-service condition or allow remote code execution.
DESERIALIZATION OF UNTRUSTED DATA CWE-502
A specially crafted communication packet sent to the affected MC Works64 platform services could cause a denial-of-service condition due to improper deserialization.
DESERIALIZATION OF UNTRUSTED DATA CWE-502
A specially crafted communication packet sent to the affected MC Works64 Workbench Pack & Go function could allow remote code execution due to improper deserialization.
IMPROPER CONTROL OF GENERATION OF CODE ('CODE INJECTION') CWE-94
A specially crafted message sent from a custom client function that interfaces to the affected MC Works64 GridWorX server may allow the execution of certain arbitrary SQL commands remotely and disclose internal data or allow internal data tampering.
DESERIALIZATION OF UNTRUSTED DATA CWE-502
A specially crafted communication packet sent to the affected MC Works64 FrameWorX server could allow remote code execution and a denial-of-service condition due to the deserialization vulnerability.