9.8
CVE-2020-5595
- EPSS 0.39%
- Veröffentlicht 07.07.2020 09:15:10
- Zuletzt bearbeitet 21.11.2024 05:34:20
- Quelle vultures@jpcert.or.jp
- CVE-Watchlists
- Unerledigt
TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains a buffer overflow vulnerability, which may allow a remote attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mitsubishielectric ≫ Coreos Version <= y
Mitsubishielectric ≫ Got2000 Gt23 Version-
Mitsubishielectric ≫ Got2000 Gt25 Version-
Mitsubishielectric ≫ Got2000 Gt27 Version-
Mitsubishielectric ≫ Got2000 Gt25 Version-
Mitsubishielectric ≫ Got2000 Gt27 Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.39% | 0.59 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.