MEDIUM🇵🇱 Wersja polska

CVE-2023-3373

CVSS 5.9v3.1pub. 2023-08-04upd. 2024-11-21

Predictable Exact Value from Previous Values vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT21 model versions 01.49.000 and prior and GOT SIMPLE Series GS21 model versions 01.49.000 and prior allows a remote unauthenticated attacker to hijack data connections (session hijacking) or prevent legitimate users from establishing data connections (to cause DoS condition) by guessing the listening port of the data connection on FTP server and connecting to it.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:L
  • Mitsubishielectric Gs21

    HW
    Mitsubishielectric
    all versions
  • Mitsubishielectric Gs21 Firmware

    OS
    Mitsubishielectric
    < 01.50.000
  • Mitsubishielectric Gt21

    HW
    Mitsubishielectric
    all versions
  • Mitsubishielectric Gt21 Firmware

    OS
    Mitsubishielectric
    < 01.50.000
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2023-0525HIGH7.5same product

Weak Encoding for Password vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions...

CVE-2023-6943CRITICAL9.8PL ✓same vendor

Unsafe Reflection w oprogramowaniu Mitsubishi Electric — zdalne wykonanie kodu

CVE-2023-4699CRITICAL10.0PL ✓same vendor

Brak uwierzytelnienia w sterownikach PLC i CNC Mitsubishi Electric — RCE

CVE-2023-4562CRITICAL9.1PL ✓same vendor

Pominięcie uwierzytelnienia w sterownikach PLC Mitsubishi MELSEC-F Series

CVE-2023-4088CRITICAL9.3PL ✓same vendor

Nieprawidłowe domyślne uprawnienia w oprogramowaniu Mitsubishi Electric GX Works3