CVE-2020-5543 Information
Feb 14, 2021
cve
Description
TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier does not properly manage sessions which allows remote attackers to stop the network functions or execute malware via a specially crafted packet.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Reference
https://jvn.jp/en/vu/JVNVU92370624/index.html https://www.mitsubishielectric.co.jp/psirt/vulnerability/pdf/2019-004.pdf
Attack Complexity
LOW
Privileges Required
NONE
User Interaction Required
NONE
Scope
NONE
Confidentiality Impact
UNCHANGED
Integrity Impact
HIGH
Availability Impact
HIGH
Base Score
HIGH
Base Severity
9.8
Share on: