QID 590611

Date Published: 2022-02-14

QID 590611: Mitsubishi Electric GOT and Tension Controller (Update A) Denial of Service (DoS) Vulnerability (ICSA-20-343-02)

AFFECTED PRODUCTS
Mitsubishi Electric reports that the vulnerability affects the following human-machine interface (GOT) and Tension Controller products:
GOT2000 series, GT21 model:


GT2107-WTBD versions v01.39.000 and earlier
GT2107-WTSD versions v01.39.000 and earlier
GT2104-RTBD versions v01.39.000 and earlier
GT2104-PMBD versions v01.39.000 and earlier
GT2103-PMBD versions v01.39.000 and earlier
Successful exploitation of this vulnerability could allow malicious attackers to cause deterioration of communication performance or cause a denial-of-service condition of the TCP communication functions of the products requiring a re-boot of the device to recover.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-20-343-02 for affected packages and patching details.
    GOT SIMPLE series, GS21 model:Workaround:

    Tension Controller

    Vendor References

    CVEs related to QID 590611

    Software Advisories
    Advisory ID Software Component Link
    ICSA-20-343-02 URL Logo www.us-cert.gov/ics/advisories/ICSA-20-343-02