Lucene search

K
cveJpcertCVE-2020-5599
HistoryJul 07, 2020 - 9:15 a.m.

CVE-2020-5599

2020-07-0709:15:10
CWE-88
jpcert
web.nvd.nist.gov
30
cve-2020-5599
mitsubishi electric
got2000 series
firmware
tcp/ip
coreos
gt27 model
gt25 model
gt23 model
vulnerability
remote attacker
network functions
malicious program
packet crafting

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.3

Confidence

High

EPSS

0.003

Percentile

71.3%

TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains an improper neutralization of argument delimiters in a command (‘Argument Injection’) vulnerability, which may allow a remote attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.

Affected configurations

Nvd
Node
mitsubishielectriccoreosRangey
AND
mitsubishielectricgot2000_gt23Match-
OR
mitsubishielectricgot2000_gt25Match-
OR
mitsubishielectricgot2000_gt27Match-
VendorProductVersionCPE
mitsubishielectriccoreos*cpe:2.3:o:mitsubishielectric:coreos:*:*:*:*:*:*:*:*
mitsubishielectricgot2000_gt23-cpe:2.3:h:mitsubishielectric:got2000_gt23:-:*:*:*:*:*:*:*
mitsubishielectricgot2000_gt25-cpe:2.3:h:mitsubishielectric:got2000_gt25:-:*:*:*:*:*:*:*
mitsubishielectricgot2000_gt27-cpe:2.3:h:mitsubishielectric:got2000_gt27:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "GOT2000 series GT27, GT25, and GT23",
    "vendor": "Mitsubishi Electric Corporation",
    "versions": [
      {
        "status": "affected",
        "version": "CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model"
      }
    ]
  }
]

CVSS2

10

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS3

9.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

AI Score

9.3

Confidence

High

EPSS

0.003

Percentile

71.3%

Related for CVE-2020-5599