First published: Thu Aug 03 2023(Updated: )
Predictable Exact Value from Previous Values vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT21 model versions 01.49.000 and prior and GOT SIMPLE Series GS21 model versions 01.49.000 and prior allows a remote unauthenticated attacker to hijack data connections (session hijacking) or prevent legitimate users from establishing data connections (to cause DoS condition) by guessing the listening port of the data connection on FTP server and connecting to it.
Credit: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Mitsubishielectric Gt21 Firmware | <01.50.000 | |
Mitsubishielectric Gt21 | ||
Mitsubishielectric Gs21 Firmware | <01.50.000 | |
Mitsubishielectric Gs21 | ||
Mitsubishi Electric GOT2000 Series, GT21 model: versions 01.49.000 and prior | ||
Mitsubishi Electric GOT SIMPLE, GS21 model: versions 01.49.000 and prior |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE ID for this vulnerability is CVE-2023-3373.
The severity rating of CVE-2023-3373 is critical with a score of 9.1.
Mitsubishi Electric Corporation GOT2000 Series GT21 model versions 01.49.000 and prior, and GOT SIMPLE Series GS21 model versions 01.49.000 and prior are affected by CVE-2023-3373.
An attacker can exploit CVE-2023-3373 to hijack data connections (session hijacking) remotely.
You can find more information about CVE-2023-3373 at the following references: [CISA Advisory](https://www.cisa.gov/news-events/ics-advisories/icsa-23-215-01), [Mitsubishi Electric PSIRT](https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-006_en.pdf), [JVN](https://jvn.jp/vu/JVNVU92167394/index.html).