CVE-2020-5648 Information

Description

Improper neutralization of argument delimiters in a command (‘Argument Injection’) vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT1455-QTBDE CoreOS version \05.65.00.BD\ and earlier GT1450-QMBDE CoreOS version \05.65.00.BD\ and earlier GT1450-QLBDE CoreOS version \05.65.00.BD\ and earlier GT1455HS-QTBDE CoreOS version \05.65.00.BD\ and earlier and GT1450HS-QMBDE CoreOS version \05.65.00.BD\ and earlier) allows unauthenticated attackers on adjacent network to stop the network functions of the products via a specially crafted packet.

Reference

https://jvn.jp/vu/JVNVU99562395/index.html https://us-cert.cisa.gov/ics/advisories/icsa-20-310-02 https://www.mitsubishielectric.co.jp/psirt/vulnerability/pdf/2020-014.pdf https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-014_en.pdf

Share on: