PT-2022-6371 · Mitsubishi · Got2000 Series Gt25+3
Published
2022-09-08
·
Updated
2023-02-09
·
CVE-2022-40268
CVSS v3.1
6.1
Medium
| Vector | AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Mitsubishi Electric Corporation GOT2000 Series GT27 versions 01.14.000 through 01.47.000
Mitsubishi Electric Corporation GOT2000 Series GT25 versions 01.14.000 through 01.47.000
Mitsubishi Electric Corporation GT SoftGOT2000 versions 1.265B through 1.285X
Description
The issue is related to the improper restriction of rendered UI layers or frames in the GOT Mobile software for Mitsubishi Electric's GOT2000 series graphic operation terminals, models GT27 and GT25, and the HMI platform GT SoftGOT2000. This can allow a remote attacker to conduct a clickjacking attack using a specially crafted web page, leading legitimate users to perform unintended operations.
Recommendations
For Mitsubishi Electric Corporation GOT2000 Series GT27 versions 01.14.000 through 01.47.000, update to a version outside of this range to mitigate the risk.
For Mitsubishi Electric Corporation GOT2000 Series GT25 versions 01.14.000 through 01.47.000, update to a version outside of this range to mitigate the risk.
For Mitsubishi Electric Corporation GT SoftGOT2000 versions 1.265B through 1.285X, update to a version outside of this range to mitigate the risk.
As a temporary workaround, consider restricting access to the vulnerable UI components until a patch is available.
Fix
Clickjacking
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Got Mobile
Got2000 Series Gt25
Got2000 Series Gt27
Gt Softgot2000