Improper Access Control in Mitsubishi Electric GOT2000 Series Firmware
CVE-2020-5598

7.5HIGH

What is CVE-2020-5598?

The firmware in the Mitsubishi Electric GOT2000 series, particularly in the GT27, GT25, and GT23 models with CoreOS version -Y and earlier, is affected by an improper access control vulnerability. This flaw could enable remote attackers to circumvent normal access restrictions, potentially halting network functions or executing malicious programs through specially crafted network packets.

Affected Version(s)

GOT2000 series GT27, GT25, and GT23 CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2020-5598 : Improper Access Control in Mitsubishi Electric GOT2000 Series Firmware