Buffer Overflow Risk in Mitsubishi GOT 1000 Series
CVE-2020-5644

9.8CRITICAL

Key Information:

Vendor
CVE Published:
6 November 2020

Summary

A buffer overflow vulnerability exists in the TCP/IP function of the firmware for the Mitsubishi GOT 1000 series. This flaw enables remote unauthenticated attackers to disrupt the device's network functions or execute arbitrary code by sending specially crafted packets. The affected models include several versions of the GT14 model, all running CoreOS version '05.65.00.BD' or earlier. Users are advised to implement recommended security measures to mitigate potential threats from this vulnerability.

Affected Version(s)

GT14 Model of GOT 1000 series (GT1455-QTBDE CoreOS version ’05.65.00.BD’ and earlier, GT1450-QMBDE CoreOS version ’05.65.00.BD’ and earlier, GT1450-QLBDE CoreOS version ’05.65.00.BD’ and earlier, GT1455HS-QTBDE CoreOS version ’05.65.00.BD’ and earlier, and GT1450HS-QMBDE CoreOS version ’05.65.00.BD’ and earlier)

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.