// For flags

CVE-2021-20590

 

Severity Score

7.5
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Improper authentication vulnerability in GOT2000 series GT27 model VNC server versions 01.39.010 and prior, GOT2000 series GT25 model VNC server versions 01.39.010 and prior, GOT2000 series GT21 model GT2107-WTBD VNC server versions 01.40.000 and prior, GOT2000 series GT21 model GT2107-WTSD VNC server versions 01.40.000 and prior, GOT SIMPLE series GS21 model GS2110-WTBD-N VNC server versions 01.40.000 and prior and GOT SIMPLE series GS21 model GS2107-WTBD-N VNC server versions 01.40.000 and prior allows a remote unauthenticated attacker to gain unauthorized access via specially crafted packets when the "VNC server" function is used.

Vulnerabilidad de autenticación inadecuada en el servidor VNC de la serie GOT2000 modelo GT27 versiones 01.39.010 y anteriores, servidor VNC de la serie GOT2000 modelo GT25 versiones 01.39.010 y anteriores, servidor VNC de la serie GOT2000 modelo GT2107-WTBD versiones 01.40.000 y anteriores, servidor VNC de la serie GOT2000 modelo GT2107-WTSD versiones 01.40. 000 y anteriores, el servidor VNC de la serie GOT SIMPLE GS21 modelo GS2110-WTBD-N versiones 01.40.000 y anteriores y el servidor VNC de la serie GOT SIMPLE GS21 modelo GS2107-WTBD-N versiones 01.40.000 y anteriores permite a un atacante remoto no autenticado obtener acceso no autorizado a través de paquetes especialmente diseñados cuando se utiliza la función "servidor VNC".

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
None
Integrity
Partial
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2020-12-17 CVE Reserved
  • 2021-04-22 CVE Published
  • 2024-04-25 EPSS Updated
  • 2024-08-03 CVE Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-287: Improper Authentication
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Mitsubishielectric
Search vendor "Mitsubishielectric"
Got2000 Gt27 Firmware
Search vendor "Mitsubishielectric" for product "Got2000 Gt27 Firmware"
<= 01.39.010
Search vendor "Mitsubishielectric" for product "Got2000 Gt27 Firmware" and version " <= 01.39.010"
-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
Got2000 Gt27
Search vendor "Mitsubishielectric" for product "Got2000 Gt27"
--
Safe
Mitsubishielectric
Search vendor "Mitsubishielectric"
Got2000 Gt25 Firmware
Search vendor "Mitsubishielectric" for product "Got2000 Gt25 Firmware"
<= 01.39.010
Search vendor "Mitsubishielectric" for product "Got2000 Gt25 Firmware" and version " <= 01.39.010"
-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
Got2000 Gt25
Search vendor "Mitsubishielectric" for product "Got2000 Gt25"
--
Safe
Mitsubishielectric
Search vendor "Mitsubishielectric"
Gt2107-wtbd Firmware
Search vendor "Mitsubishielectric" for product "Gt2107-wtbd Firmware"
<= 01.40.000
Search vendor "Mitsubishielectric" for product "Gt2107-wtbd Firmware" and version " <= 01.40.000"
-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
Gt2107-wtbd
Search vendor "Mitsubishielectric" for product "Gt2107-wtbd"
--
Safe
Mitsubishielectric
Search vendor "Mitsubishielectric"
Gt2107-wtsd Firmware
Search vendor "Mitsubishielectric" for product "Gt2107-wtsd Firmware"
<= 01.40.000
Search vendor "Mitsubishielectric" for product "Gt2107-wtsd Firmware" and version " <= 01.40.000"
-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
Gt2107-wtsd
Search vendor "Mitsubishielectric" for product "Gt2107-wtsd"
--
Safe
Mitsubishielectric
Search vendor "Mitsubishielectric"
Gs2110-wtbd-n Firmware
Search vendor "Mitsubishielectric" for product "Gs2110-wtbd-n Firmware"
<= 01.40.000
Search vendor "Mitsubishielectric" for product "Gs2110-wtbd-n Firmware" and version " <= 01.40.000"
-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
Gs2110-wtbd-n
Search vendor "Mitsubishielectric" for product "Gs2110-wtbd-n"
--
Safe
Mitsubishielectric
Search vendor "Mitsubishielectric"
Gs2107-wtbd-n Firmware
Search vendor "Mitsubishielectric" for product "Gs2107-wtbd-n Firmware"
<= 01.40.000
Search vendor "Mitsubishielectric" for product "Gs2107-wtbd-n Firmware" and version " <= 01.40.000"
-
Affected
in Mitsubishielectric
Search vendor "Mitsubishielectric"
Gs2107-wtbd-n
Search vendor "Mitsubishielectric" for product "Gs2107-wtbd-n"
--
Safe