QID 591193

Date Published: 2022-11-21

QID 591193: Mitsubishi Electric GT SoftGOT2000 OS COMMAND INJECTION Vulnerability (ICSA-22-319-01, 2022-012)

AFFECTED PRODUCTS
Mitsubishi Electric reports this vulnerability affects OpenSSL in the following products: GT SoftGOT2000 1.275M-1.280S

QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys

Successful exploitation of this vulnerability could allow an attacker to execute malicious OS commands.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution

    Customers are advised to refer to Schneider Electric MITIGATIONS section icsa-22-319-01 for affected packages and patching details.

    Vendor References

    CVEs related to QID 591193

    Software Advisories
    Advisory ID Software Component Link
    2022-012 URL Logo www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-012_en.pdf
    icsa-22-319-01 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-22-319-01