Vulnerabilities > Mitsubishielectric

DATE CVE VULNERABILITY TITLE RISK
2020-07-16 CVE-2020-12009 Deserialization of Untrusted Data vulnerability in multiple products
A specially crafted communication packet sent to the affected device could cause a denial-of-service condition due to a deserialization vulnerability.
network
low complexity
mitsubishielectric iconics CWE-502
5.0
2020-07-16 CVE-2020-12011 Out-of-bounds Write vulnerability in multiple products
A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition or allow remote code execution.
network
low complexity
mitsubishielectric iconics CWE-787
7.5
2020-07-07 CVE-2020-5600 Resource Exhaustion vulnerability in Mitsubishielectric Coreos 05.65.00.Bd/Y
TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains a resource management error vulnerability, which may allow a remote attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.
network
low complexity
mitsubishielectric CWE-400
5.0
2020-07-07 CVE-2020-5599 Injection vulnerability in Mitsubishielectric Coreos 05.65.00.Bd/Y
TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains an improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability, which may allow a remote attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.
network
low complexity
mitsubishielectric CWE-74
critical
10.0
2020-07-07 CVE-2020-5598 Incorrect Authorization vulnerability in Mitsubishielectric Coreos 05.65.00.Bd/Y
TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains an improper access control vulnerability, which may which may allow a remote attacker tobypass access restriction and stop the network functions of the products or execute a malicious program via a specially crafted packet.
network
low complexity
mitsubishielectric CWE-863
5.0
2020-07-07 CVE-2020-5597 NULL Pointer Dereference vulnerability in Mitsubishielectric Coreos Y
TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains a null pointer dereference vulnerability, which may allow a remote attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.
network
low complexity
mitsubishielectric CWE-476
5.0
2020-07-07 CVE-2020-5596 Session Fixation vulnerability in Mitsubishielectric Coreos Y
TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) does not properly manage sessions, which may allow a remote attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.
network
low complexity
mitsubishielectric CWE-384
5.0
2020-07-07 CVE-2020-5595 Classic Buffer Overflow vulnerability in Mitsubishielectric Coreos Y
TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains a buffer overflow vulnerability, which may allow a remote attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.
network
low complexity
mitsubishielectric CWE-120
7.5
2020-06-30 CVE-2020-5603 Resource Exhaustion vulnerability in Mitsubishielectric products
Uncontrolled resource consumption vulnerability in Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver.
network
low complexity
mitsubishielectric CWE-400
5.0
2020-06-30 CVE-2020-5602 XXE vulnerability in Mitsubishielectric products
Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver.
network
low complexity
mitsubishielectric CWE-611
5.0