Vulnerabilities > Mitsubishielectric

DATE CVE VULNERABILITY TITLE RISK
2020-07-16 CVE-2020-12009 Deserialization of Untrusted Data vulnerability in multiple products
A specially crafted communication packet sent to the affected device could cause a denial-of-service condition due to a deserialization vulnerability.
network
low complexity
mitsubishielectric iconics CWE-502
7.5
2020-07-16 CVE-2020-12011 Out-of-bounds Write vulnerability in multiple products
A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition or allow remote code execution.
network
low complexity
mitsubishielectric iconics CWE-787
critical
9.8
2020-07-07 CVE-2020-5600 Unspecified vulnerability in Mitsubishielectric Coreos 05.65.00.Bd/Y
TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains a resource management error vulnerability, which may allow a remote attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.
network
low complexity
mitsubishielectric
7.5
2020-07-07 CVE-2020-5599 Argument Injection or Modification vulnerability in Mitsubishielectric Coreos 05.65.00.Bd/Y
TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains an improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability, which may allow a remote attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.
network
low complexity
mitsubishielectric CWE-88
critical
9.8
2020-07-07 CVE-2020-5598 Unspecified vulnerability in Mitsubishielectric Coreos 05.65.00.Bd/Y
TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains an improper access control vulnerability, which may which may allow a remote attacker tobypass access restriction and stop the network functions of the products or execute a malicious program via a specially crafted packet.
network
low complexity
mitsubishielectric
7.5
2020-07-07 CVE-2020-5597 NULL Pointer Dereference vulnerability in Mitsubishielectric Coreos 05.65.00.Bd/Y
TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains a null pointer dereference vulnerability, which may allow a remote attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.
network
low complexity
mitsubishielectric CWE-476
7.5
2020-07-07 CVE-2020-5596 Session Fixation vulnerability in Mitsubishielectric Coreos 05.65.00.Bd/Y
TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) does not properly manage sessions, which may allow a remote attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.
network
low complexity
mitsubishielectric CWE-384
7.5
2020-07-07 CVE-2020-5595 Classic Buffer Overflow vulnerability in Mitsubishielectric Coreos 05.65.00.Bd/Y
TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains a buffer overflow vulnerability, which may allow a remote attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.
network
low complexity
mitsubishielectric CWE-120
critical
9.8
2020-06-30 CVE-2020-5603 Resource Exhaustion vulnerability in Mitsubishielectric products
Uncontrolled resource consumption vulnerability in Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver.
network
low complexity
mitsubishielectric CWE-400
7.5
2020-06-30 CVE-2020-5602 XXE vulnerability in Mitsubishielectric products
Mitsubishi Electoric FA Engineering Software (CPU Module Logging Configuration Tool Ver.
network
low complexity
mitsubishielectric CWE-611
7.5