Session Management Flaw in Mitsubishi Electric GOT2000 Series Network Functions
CVE-2020-5596
7.5HIGH
Key Information:
- Vendor
- CVE Published:
- 7 July 2020
Summary
The TCP/IP function within the firmware of Mitsubishi Electric's GOT2000 series devices fails to adequately manage sessions, enabling remote attackers to disrupt network functions or execute malicious programs by sending specially crafted packets. This vulnerability poses a risk to the integrity and availability of affected products, necessitating immediate attention to secure affected installations against potential attacks.
Affected Version(s)
GOT2000 series GT27, GT25, and GT23 CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved