Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-5gwg-q76w-25g7

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains an improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability, which may allow a remote attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.

TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains an improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability, which may allow a remote attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.

EPSS

Процентиль: 79%
0.01256
Низкий

Дефекты

CWE-74

Связанные уязвимости

CVSS3: 9.8
nvd
больше 5 лет назад

TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains an improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability, which may allow a remote attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.

EPSS

Процентиль: 79%
0.01256
Низкий

Дефекты

CWE-74