9.8
CVE-2020-5644
- EPSS 1.17%
- Veröffentlicht 06.11.2020 03:15:17
- Zuletzt bearbeitet 21.11.2024 05:34:24
- Quelle vultures@jpcert.or.jp
- CVE-Watchlists
- Unerledigt
Buffer overflow vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT1455-QTBDE CoreOS version "05.65.00.BD" and earlier, GT1450-QMBDE CoreOS version "05.65.00.BD" and earlier, GT1450-QLBDE CoreOS version "05.65.00.BD" and earlier, GT1455HS-QTBDE CoreOS version "05.65.00.BD" and earlier, and GT1450HS-QMBDE CoreOS version "05.65.00.BD" and earlier) allows a remote unauthenticated attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mitsubishielectric ≫ Coreos Version <= 05.65.00.bd
Mitsubishielectric ≫ Gt1450-qlbde Version-
Mitsubishielectric ≫ Gt1450-qmbde Version-
Mitsubishielectric ≫ Gt1450hs-qmbde Version-
Mitsubishielectric ≫ Gt1455-qtbde Version-
Mitsubishielectric ≫ Gt1455hs-qtbde Version-
Mitsubishielectric ≫ Gt1450-qmbde Version-
Mitsubishielectric ≫ Gt1450hs-qmbde Version-
Mitsubishielectric ≫ Gt1455-qtbde Version-
Mitsubishielectric ≫ Gt1455hs-qtbde Version-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.17% | 0.78 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 7.5 | 10 | 6.4 |
AV:N/AC:L/Au:N/C:P/I:P/A:P
|
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.