QID 590724

Date Published: 2022-04-04

QID 590724: Mitsubishi Electric GOT and Tension Controller (Update A) Vulnerability (ICSA-21-131-02)

AFFECTED PRODUCTS
Mitsubishi Electric reports the vulnerability affects the MODBUS/TCP slave communication function of the following devices:
GT SoftGOT2000: Versions 1.170C - 1.250L

QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys

Successful exploitation of this vulnerability may be able to stop the communication function of the products, requiring a reset to regain functionality.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ICSA-21-131-02 for affected packages and patching details.
    GOT SIMPLE series

    Vendor References

    CVEs related to QID 590724

    Software Advisories
    Advisory ID Software Component Link
    ICSA-21-131-02 URL Logo www.us-cert.gov/ics/advisories/ICSA-21-131-02