QID 591104

Date Published: 2022-10-14

QID 591104: Mitsubishi Electric GT25-WLAN (Update A) Multiple Vulnerabilities (ICSA-22-102-04)

AFFECTED PRODUCTS
The following versions of Wireless LAN communication unit GT25-WLAN in GOT2000 Series GT25 or GT27, are affected: GT25-WLAN: Version 01.39.000 and earlier

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

There are multiple vulnerabilities due to design flaws in the frame fragmentation functionality and the frame aggregation functionality in the Wireless Communication Standards IEEE 802.11. These vulnerabilities could allow an attacker to steal communication contents or inject unauthorized packets.

  • CVSS V3 rated as High - 6.5 severity.
  • CVSS V2 rated as Medium - 3.3 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section icsa-22-102-04 for affected packages and patching details.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    icsa-22-102-04 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-22-102-04