// For flags

CVE-2021-20589

 

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Buffer access with incorrect length value vulnerability in GOT2000 series GT27 model communication driver versions 01.19.000 through 01.38.000, GT25 model communication driver versions 01.19.000 through 01.38.000, GT23 model communication driver versions 01.19.000 through 01.38.000 and GT21 model communication driver versions 01.21.000 through 01.39.000, GOT SIMPLE series GS21 model communication driver versions 01.21.000 through 01.39.000, GT SoftGOT2000 versions 1.170C through 1.250L and Tension Controller LE7-40GU-L Screen package data for MODBUS/TCP V1.00 allows a remote unauthenticated attacker to stop the communication function of the products via specially crafted packets.

Una Vulnerabilidad de Acceso del Búfer de valor de longitud incorrecto en GOT2000 series GT27 model communication driver versiones 01.19.000 hasta 01.38.000, GT25 model communication driver versiones 01.19.000 hasta 01.38.000, GT23 model communication driver versiones 01.19.000 hasta 01.38.000 y GT21 model communication driver versiones 01.21.000 hasta 01.39.000, GOT SIMPLE series GS21 model communication driver versiones 01.21.000 hasta 01.39.000, GT SoftGOT2000 versiones 1.170C hasta 1.250L y el paquete de datos de Pantalla Tension Controller LE7-40GU-L para MODBUS/TCP versión V1.00, permite a un atacante remoto no autenticado detener la función de comunicación de los productos por medio de paquetes especialmente diseñados

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
None
Integrity
None
Availability
Partial
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-12-17 CVE Reserved
  • 2021-05-19 CVE Published
  • 2024-02-02 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mitsubishi
Search vendor "Mitsubishi"
Gt27 Firmware
Search vendor "Mitsubishi" for product "Gt27 Firmware"
>= 01.19.000 <= 01.38.000
Search vendor "Mitsubishi" for product "Gt27 Firmware" and version " >= 01.19.000 <= 01.38.000"
-
Affected
in Mitsubishi
Search vendor "Mitsubishi"
Gt27
Search vendor "Mitsubishi" for product "Gt27"
--
Safe
Mitsubishi
Search vendor "Mitsubishi"
Gt25 Firmware
Search vendor "Mitsubishi" for product "Gt25 Firmware"
>= 01.19.000 <= 01.38.000
Search vendor "Mitsubishi" for product "Gt25 Firmware" and version " >= 01.19.000 <= 01.38.000"
-
Affected
in Mitsubishi
Search vendor "Mitsubishi"
Gt25
Search vendor "Mitsubishi" for product "Gt25"
--
Safe
Mitsubishi
Search vendor "Mitsubishi"
Gt23 Firmware
Search vendor "Mitsubishi" for product "Gt23 Firmware"
>= 01.19.000 <= 01.38.000
Search vendor "Mitsubishi" for product "Gt23 Firmware" and version " >= 01.19.000 <= 01.38.000"
-
Affected
in Mitsubishi
Search vendor "Mitsubishi"
Gt23
Search vendor "Mitsubishi" for product "Gt23"
--
Safe
Mitsubishi
Search vendor "Mitsubishi"
Gt21 Firmware
Search vendor "Mitsubishi" for product "Gt21 Firmware"
>= 01.21.000 <= 01.39.000
Search vendor "Mitsubishi" for product "Gt21 Firmware" and version " >= 01.21.000 <= 01.39.000"
-
Affected
in Mitsubishi
Search vendor "Mitsubishi"
Gt21
Search vendor "Mitsubishi" for product "Gt21"
--
Safe
Mitsubishi
Search vendor "Mitsubishi"
Gs21 Firmware
Search vendor "Mitsubishi" for product "Gs21 Firmware"
>= 01.21.000 <= 01.39.000
Search vendor "Mitsubishi" for product "Gs21 Firmware" and version " >= 01.21.000 <= 01.39.000"
-
Affected
in Mitsubishi
Search vendor "Mitsubishi"
Gs21
Search vendor "Mitsubishi" for product "Gs21"
--
Safe
Mitsubishi
Search vendor "Mitsubishi"
Gt Softgot2000 Firmware
Search vendor "Mitsubishi" for product "Gt Softgot2000 Firmware"
>= 1.170c <= 1.250l
Search vendor "Mitsubishi" for product "Gt Softgot2000 Firmware" and version " >= 1.170c <= 1.250l"
-
Affected
in Mitsubishi
Search vendor "Mitsubishi"
Gt Softgot2000
Search vendor "Mitsubishi" for product "Gt Softgot2000"
--
Safe