CVE-2020-5545: Critical severity Mitsubishielectric Iu1-1m20-d Firmware vulnerability
TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier allows remote attackers to bypass access restriction and to stop the network functions or execute malware via a specially crafted packet.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Mitsubishi Electric MELQIC IU1 series (IU1-1M20-D)to a version that resolves this vulnerability.Fixed in 1.0.7 and earlier - Compensating control
Isolate or firewall the affected MELQIC IU1 series (IU1-1M20-D) devices so they are not reachable by untrusted remote attackers, since a crafted packet can bypass access restrictions and stop network functions or execute malware.
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-5545.
What is the severity of CVE-2020-5545?
CVE-2020-5545 has a severity score of 9.8, which is considered critical.
What is the affected software for CVE-2020-5545?
The affected software for CVE-2020-5545 is Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier.
How can remote attackers exploit CVE-2020-5545?
Remote attackers can exploit CVE-2020-5545 by bypassing access restriction and stopping network functions or executing malware via a specially crafted packet.
Is there a fix available for CVE-2020-5545?
It is recommended to update to a patched version of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware to fix CVE-2020-5545.