CVE-2022-40266
Published on: Not Yet Published
Last Modified on: 11/30/2022 08:02:00 PM UTC
Certain versions of Got2000 Gt23 from Mitsubishielectric contain the following vulnerability:
Improper Input Validation vulnerability in Mitsubishi Electric GOT2000 Series GT27 model FTP server versions 01.39.000 and prior, Mitsubishi Electric GOT2000 Series GT25 model FTP server versions 01.39.000 and prior and Mitsubishi Electric GOT2000 Series GT23 model FTP server versions 01.39.000 and prior allows a remote authenticated attacker to cause a Denial of Service condition by sending specially crafted command.
- CVE-2022-40266 has been assigned by
[email protected] to track the vulnerability - currently rated as MEDIUM severity.
- Affected Vendor/Software:
Mitsubishi Electric - GOT2000 Series GT27 model version = FTP server versions 01.39.000 and prior
- Affected Vendor/Software:
Mitsubishi Electric - GOT2000 Series GT25 model version = FTP server versions 01.39.000 and prior
- Affected Vendor/Software:
Mitsubishi Electric - GOT2000 Series GT23 model version = FTP server versions 01.39.000 and prior
CVSS3 Score: 6.5 - MEDIUM
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
NETWORK | LOW | LOW | NONE |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | NONE | NONE | HIGH |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
www.mitsubishielectric.com application/pdf |
![]() | |
JVNVU#95633416: 三菱電機製GOT2000シリーズのFTPサーバ機能における不適切な入力確認の脆弱性 | jvn.jp text/xml |
![]() |
Related QID Numbers
- 591247 Mitsubishi Electric GOT2000 Series Improper Input Validation Vulnerability (ICSA-22-333-01, 2022-016)
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Hardware
| Mitsubishielectric | Got2000 Gt23 | - | All | All | All |
Operating System | Mitsubishielectric | Got2000 Gt23 Firmware | All | All | All | All |
Hardware
| Mitsubishielectric | Got2000 Gt25 | - | All | All | All |
Operating System | Mitsubishielectric | Got2000 Gt25 Firmware | All | All | All | All |
Hardware
| Mitsubishielectric | Got2000 Gt27 | - | All | All | All |
Operating System | Mitsubishielectric | Got2000 Gt27 Firmware | All | All | All | All |
- cpe:2.3:h:mitsubishielectric:got2000_gt23:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:got2000_gt23_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:got2000_gt25:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:got2000_gt25_firmware:*:*:*:*:*:*:*:*:
- cpe:2.3:h:mitsubishielectric:got2000_gt27:-:*:*:*:*:*:*:*:
- cpe:2.3:o:mitsubishielectric:got2000_gt27_firmware:*:*:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2022-40266 : Improper Input Validation vulnerability in Mitsubishi Electric GOT2000 Series GT27 model FTP serve… twitter.com/i/web/status/1… | 2022-11-24 09:04:20 |
![]() |
CVE-2022-40266 | 2022-11-24 10:38:41 |