Resource management error in Mitsubishi Electric products - CVE-2020-5600

 

Resource management error in Mitsubishi Electric products - CVE-2020-5600

Published: July 8, 2020 / Updated: July 15, 2020


Vulnerability identifier: #VU29597
CSH Severity: Medium
CVSS v4: 6.9 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2020-5600
CWE-ID: CWE-399
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to gain access to sensitive information on the system

The vulnerability exists due to improper management of internal resources with the application in the TCP/IP function. A remote attacker can pass specially crafted data to the application and obtain sensitive information on the target system.


Affected software

GOT2000 GT27 model
GOT2000 GT25 model
GOT2000 GT23 model

How to mitigate CVE-2020-5600

Install updates from vendor's website.


External References

Related Security Bulletins