Mitsubishi Electric Corporation is working on a fix, but has a plan to handle an out-of-bounds read vulnerability in its GOT and Tension Controller products, according to a report with CISA.

Successful exploitation of this remotely exploitable vulnerability could allow attackers to cause deterioration of communication performance or cause a denial-of-service condition of the TCP communication functions of the products.

  • Mitsubishi Electric reports the vulnerability, which it self-reported, affects the following human-machine interface (GOT) and Tension Controller products:
  • GOT2000 series, GT21 model:
    GT2107-WTBD All versions
    GT2107-WTSD All versions
    GT2104-RTBD All versions
    GT2104-PMBD All versions
    GT2103-PMBD All versions
  • GOT SIMPLE series, GS21 model:
    GS2110-WTBD All versions
    GS2107-WTBD All versions
  • Tension Controller:
    LE7-40GU-L All versions

In the vulnerability, there is an out-of-bounds read issue that may allow attackers to cause deterioration in communication performance or cause a denial-of-service condition of the TCP communication functions of the products by sending specially crafted packets.

CVE-2020-5675 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 7.5.

Schneider Bold

The product sees use mainly in the critical manufacturing sector, and on a global basis.

No known public exploits specifically target this vulnerability. However, an attacker with low skill level could leverage the vulnerability.

Mitsubishi Electric will release a fixed version in the near future. Until then, they ask users to restrict access to the product only from trusted networks and hosts.

Click on the Mitsubishi Electric website for details.

Additional information about the vulnerability or Mitsubishi Electric’s recommendation is available by contacting a Mitsubishi Electric representative.

ISSSource

Pin It on Pinterest

Share This