PT-2020-18612 · Mitsubishi · Got 1000 Series

Published

2020-11-06

·

Updated

2020-11-20

·

CVE-2020-5645

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions GOT 1000 series GT1455-QTBDE CoreOS versions prior to 05.65.00.BD GOT 1000 series GT1450-QMBDE CoreOS versions prior to 05.65.00.BD GOT 1000 series GT1450-QLBDE CoreOS versions prior to 05.65.00.BD GOT 1000 series GT1455HS-QTBDE CoreOS versions prior to 05.65.00.BD GOT 1000 series GT1450HS-QMBDE CoreOS versions prior to 05.65.00.BD
Description A session fixation issue in the TCP/IP function of the GOT 1000 series allows a remote unauthenticated attacker to stop the network functions of the products via a specially crafted packet.
Recommendations For GOT 1000 series GT1455-QTBDE CoreOS versions prior to 05.65.00.BD, update to a version later than 05.65.00.BD. For GOT 1000 series GT1450-QMBDE CoreOS versions prior to 05.65.00.BD, update to a version later than 05.65.00.BD. For GOT 1000 series GT1450-QLBDE CoreOS versions prior to 05.65.00.BD, update to a version later than 05.65.00.BD. For GOT 1000 series GT1455HS-QTBDE CoreOS versions prior to 05.65.00.BD, update to a version later than 05.65.00.BD. For GOT 1000 series GT1450HS-QMBDE CoreOS versions prior to 05.65.00.BD, update to a version later than 05.65.00.BD.

Fix

Session Fixation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-5645

Affected Products

Got 1000 Series