Session Hijacking and Denial of Service Vulnerability in Mitsubishi Electric GOT2000 and GOT SIMPLE Series
CVE-2023-3373
5.9MEDIUM
Key Information:
- Vendor
- CVE Published:
- 4 August 2023
What is CVE-2023-3373?
A vulnerability exists in Mitsubishi Electric's GOT2000 Series GT21 and GOT SIMPLE Series GS21 models, allowing remote unauthenticated attackers to hijack data connections or disrupt services. This is achieved through an exploitation of predictable port values, enabling attackers to guess the listening port of the FTP server. Successful exploitation can lead to unauthorized access or denial of service for legitimate users, affecting the integrity and availability of systems relying on these models.
Affected Version(s)
GOT SIMPLE Series GS21 model 01.49.000 and prior
GOT2000 Series GT21 model 01.49.000 and prior