Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-5546

Опубликовано: 16 мар. 2020
Источник: nvd
CVSS3: 8.8
CVSS2: 5.8
EPSS Низкий

Описание

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier allows an attacker on the same network segment to stop the network functions or execute malware via a specially crafted packet.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:mitsubishielectric:iu1-1m20-d_firmware:*:*:*:*:*:*:*:*
Версия до 1.0.7 (включая)
cpe:2.3:h:mitsubishielectric:iu1-1m20-d:-:*:*:*:*:*:*:*

EPSS

Процентиль: 37%
0.00162
Низкий

8.8 High

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-88

Связанные уязвимости

github
больше 3 лет назад

Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier allows an attacker on the same network segment to stop the network functions or execute malware via a specially crafted packet.

EPSS

Процентиль: 37%
0.00162
Низкий

8.8 High

CVSS3

5.8 Medium

CVSS2

Дефекты

CWE-88