PT-2023-9782 · Mitsubishi · Got Simple Series+1

CVE-2023-3373

·

Publicado

2023-08-03

·

Atualizado

2023-08-10

CVSS v3.1

9.1

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Name of the Vulnerable Software and Affected Versions Mitsubishi Electric Corporation GOT2000 Series GT21 model versions 01.49.000 and prior Mitsubishi Electric Corporation GOT SIMPLE Series GS21 model versions 01.49.000 and prior
Description The issue is related to a Predictable Exact Value from Previous Values vulnerability, which allows a remote unauthenticated attacker to hijack data connections or prevent legitimate users from establishing data connections. This can be achieved by guessing the listening port of the data connection on the FTP server and connecting to it, potentially leading to session hijacking or a Denial of Service (DoS) condition.
Recommendations For Mitsubishi Electric Corporation GOT2000 Series GT21 model versions 01.49.000 and prior: update to a version later than 01.49.000 to resolve the issue. For Mitsubishi Electric Corporation GOT SIMPLE Series GS21 model versions 01.49.000 and prior: update to a version later than 01.49.000 to resolve the issue. As a temporary workaround, consider restricting access to the FTP server to minimize the risk of exploitation.

Correção

Use of Insufficiently Random Values

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2024-10625
CVE-2023-3373

Produtos afetados

Got Simple Series
Got2000 Series