PT-2023-9782 · Mitsubishi · Got Simple Series+1
Published
2023-08-03
·
Updated
2023-08-10
·
CVE-2023-3373
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Mitsubishi Electric Corporation GOT2000 Series GT21 model versions 01.49.000 and prior
Mitsubishi Electric Corporation GOT SIMPLE Series GS21 model versions 01.49.000 and prior
Description
The issue is related to a Predictable Exact Value from Previous Values vulnerability, which allows a remote unauthenticated attacker to hijack data connections or prevent legitimate users from establishing data connections. This can be achieved by guessing the listening port of the data connection on the FTP server and connecting to it, potentially leading to session hijacking or a Denial of Service (DoS) condition.
Recommendations
For Mitsubishi Electric Corporation GOT2000 Series GT21 model versions 01.49.000 and prior: update to a version later than 01.49.000 to resolve the issue.
For Mitsubishi Electric Corporation GOT SIMPLE Series GS21 model versions 01.49.000 and prior: update to a version later than 01.49.000 to resolve the issue.
As a temporary workaround, consider restricting access to the FTP server to minimize the risk of exploitation.
Fix
Use of Insufficiently Random Values
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Got Simple Series
Got2000 Series