Missing Synchronization in Mitsubishi Electric products - CVE-2021-20592
Published: July 28, 2021
Vulnerability identifier: #VU55382
CSH Severity: Medium
CVSS v4 BT: 4.6 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green]
CVE-ID: CVE-2021-20592
CWE-ID: CWE-820
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of servise (DoS) attack.
The vulnerability exists due to the affected software utilizes a shared resource in a concurrent manner but does not attempt to synchronize access to the resource. A remote attacker can cause a denial of service condition on the target system.
Affected software
GOT2000 GT27 model
GOT2000 GT25 model
GOT2000 GT23 model
GT SoftGOT2000
GOT2000 GT25 model
GOT2000 GT23 model
GT SoftGOT2000
How to mitigate CVE-2021-20592
Install updates from vendor's website.
GOT2000 GT27 model - update to 01.40.000
GOT2000 GT25 model - update to 01.40.000
GOT2000 GT23 model - update to 01.40.000
GT SoftGOT2000 - update to 1.260W
GOT2000 GT25 model - update to 01.40.000
GOT2000 GT23 model - update to 01.40.000
GT SoftGOT2000 - update to 1.260W