First published: Thu Aug 03 2023(Updated: )
Predictable Exact Value from Previous Values vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT21 model versions 01.49.000 and prior and GOT SIMPLE Series GS21 model versions 01.49.000 and prior allows a remote unauthenticated attacker to hijack data connections (session hijacking) or prevent legitimate users from establishing data connections (to cause DoS condition) by guessing the listening port of the data connection on FTP server and connecting to it.
Credit: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Mitsubishi Electric GOT2000 Series, GT21 model | ||
Mitsubishi Electric GOT SIMPLE (Models GS25, GS21) | ||
Mitsubishi Electric GT21 Firmware | <01.50.000 | |
Mitsubishi Electric GT21 | ||
Mitsubishi Electric GS21 Firmware | <01.50.000 | |
Mitsubishi Electric GS21 Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The CVE ID for this vulnerability is CVE-2023-3373.
The severity rating of CVE-2023-3373 is critical with a score of 9.1.
Mitsubishi Electric Corporation GOT2000 Series GT21 model versions 01.49.000 and prior, and GOT SIMPLE Series GS21 model versions 01.49.000 and prior are affected by CVE-2023-3373.
An attacker can exploit CVE-2023-3373 to hijack data connections (session hijacking) remotely.
You can find more information about CVE-2023-3373 at the following references: [CISA Advisory](https://www.cisa.gov/news-events/ics-advisories/icsa-23-215-01), [Mitsubishi Electric PSIRT](https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2023-006_en.pdf), [JVN](https://jvn.jp/vu/JVNVU92167394/index.html).