CVE-2021-20589
Buffer access with incorrect length value vulnerability in GOT2000 series GT27 model communication driver versions 01.19.000 through 01.38.000, GT25 model communication driver versions 01.19.000 through 01.38.000, GT23 model communication driver versions 01.19.000 through 01.38.000 and GT21 model communication driver versions 01.21.000 through 01.39.000, GOT SIMPLE series GS21 model communication driver versions 01.21.000 through 01.39.000, GT SoftGOT2000 versions 1.170C through 1.250L and Tension Controller LE7-40GU-L Screen package data for MODBUS/TCP V1.00 allows a remote unauthenticated attacker to stop the communication function of the products via specially crafted packets.
Published:May 19, 2021
Last Modified:Nov 21, 2024
EPS:May 19, 2021
EPSS Score:0.00326
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Mitsubishi
Product
Gs21
Mitsubishi
Gs21
Vendor
Mitsubishi
Product
Gs21 Firmware
Mitsubishi
Gs21 Firmware
Vendor
Mitsubishi
Product
Gt21
Mitsubishi
Gt21
Vendor
Mitsubishi
Product
Gt21 Firmware
Mitsubishi
Gt21 Firmware
Vendor
Mitsubishi
Product
Gt23
Mitsubishi
Gt23
Vendor
Mitsubishi
Product
Gt23 Firmware
Mitsubishi
Gt23 Firmware
Vendor
Mitsubishi
Product
Gt25
Mitsubishi
Gt25
Vendor
Mitsubishi
Product
Gt25 Firmware
Mitsubishi
Gt25 Firmware
Vendor
Mitsubishi
Product
Gt27
Mitsubishi
Gt27
Vendor
Mitsubishi
Product
Gt27 Firmware
Mitsubishi
Gt27 Firmware
Vendor
Mitsubishi
Product
Gt Softgot2000
Mitsubishi
Gt Softgot2000
Vendor
Mitsubishi
Product
Gt Softgot2000 Firmware
Mitsubishi
Gt Softgot2000 Firmware
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
