CVE-2021-20601

HIGHCVSS 7.5/10EPSS 2.28%

Last modified

CVE-2021-20601 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Improper input validation vulnerability in GOT2000 series GT27 model all versions, GOT2000 series GT25 model all versions, GOT2000 series GT23 model all versions, GOT2000 series GT21 model all versions, GOT SIMPLE series GS21 model all versions, and GT SoftGOT2000 all versions allows an remote unauthenticated attacker to write a value that exceeds the configured input range limit by sending a malicious packet to rewrite the device value. As a result, the system operation may be affected, such as malfunction.. EPSS estimates a 2.28% chance of exploitation in the next 30 days.

Description

Improper input validation vulnerability in GOT2000 series GT27 model all versions, GOT2000 series GT25 model all versions, GOT2000 series GT23 model all versions, GOT2000 series GT21 model all versions, GOT SIMPLE series GS21 model all versions, and GT SoftGOT2000 all versions allows an remote unauthenticated attacker to write a value that exceeds the configured input range limit by sending a malicious packet to rewrite the device value. As a result, the system operation may be affected, such as malfunction.

Metrics

CVSS 3.1
7.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

EPSS Probability
2.28%

80.9th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
MitsubishielectricGt Softgot2000All versions
MitsubishielectricGot Simple Gs2110-Wtbd FirmwareAll versions
MitsubishielectricGot Simple Gs2107-Wtbd FirmwareAll versions
MitsubishielectricGot2000 Gt2104-Rtbd FirmwareAll versions
MitsubishielectricGot2000 Gt2103-Pmbd FirmwareAll versions
MitsubishielectricGot2000 Gt2103-Pmbds FirmwareAll versions
MitsubishielectricGot2000 Gt2103-Pmbds2 FirmwareAll versions
MitsubishielectricGot2000 Gt2103-Pmbls FirmwareAll versions
MitsubishielectricGot2000 Gt2107-Wtbd FirmwareAll versions
MitsubishielectricGot2000 Gt2310-Vtba FirmwareAll versions
MitsubishielectricGot2000 Gt2310-Vtbd FirmwareAll versions
MitsubishielectricGot2000 Gt2308-Vtbd FirmwareAll versions
MitsubishielectricGot2000 Gt2308-Vtba FirmwareAll versions
MitsubishielectricGot2000 Gt2507t-Wtsd FirmwareAll versions
MitsubishielectricGot2000 Gt2507-Wtsd FirmwareAll versions
MitsubishielectricGot2000 Gt2507-Wtbd FirmwareAll versions
MitsubishielectricGot2000 Gt2512-Wxtsd FirmwareAll versions
MitsubishielectricGot2000 Gt2510-Wxtbd FirmwareAll versions
MitsubishielectricGot2000 Gt2510-Wxtsd FirmwareAll versions
MitsubishielectricGot2000 Gt2512-Wxtbd FirmwareAll versions
MitsubishielectricGot2000 Gt2505hs-Vtbd FirmwareAll versions
MitsubishielectricGot2000 Gt2506hs-Vtbd FirmwareAll versions
MitsubishielectricGot2000 Gt2512-Stba FirmwareAll versions
MitsubishielectricGot2000 Gt2512-Stbd FirmwareAll versions
MitsubishielectricGot2000 Gt2510-Vtba FirmwareAll versions
MitsubishielectricGot2000 Gt2510-Vtbd FirmwareAll versions
MitsubishielectricGot2000 Gt2510-Vtwa FirmwareAll versions
MitsubishielectricGot2000 Gt2510-Vtwd FirmwareAll versions
MitsubishielectricGot2000 Gt2508-Vtba FirmwareAll versions
MitsubishielectricGot2000 Gt2508-Vtbd FirmwareAll versions
MitsubishielectricGot2000 Gt2508-Vtwa FirmwareAll versions
MitsubishielectricGot2000 Gt2508-Vtwd FirmwareAll versions
MitsubishielectricGot2000 Gt2505-Vtbd FirmwareAll versions
MitsubishielectricGot2000 Gt2705-Vtbd FirmwareAll versions
MitsubishielectricGot2000 Gt2708-Vtbd FirmwareAll versions
MitsubishielectricGot2000 Gt2708-Vtba FirmwareAll versions
MitsubishielectricGot2000 Gt2708-Stba FirmwareAll versions
MitsubishielectricGot2000 Gt2708-Stbd FirmwareAll versions
MitsubishielectricGot2000 Gt2710-Stba FirmwareAll versions
MitsubishielectricGot2000 Gt2710-Stbd FirmwareAll versions
MitsubishielectricGot2000 Gt2710-Vtba FirmwareAll versions
MitsubishielectricGot2000 Gt2710-Vtbd FirmwareAll versions
MitsubishielectricGot2000 Gt2710-Vtwa FirmwareAll versions
MitsubishielectricGot2000 Gt2710-Vtwd FirmwareAll versions
MitsubishielectricGot2000 Gt2712-Stwd FirmwareAll versions
MitsubishielectricGot2000 Gt2712-Stwa FirmwareAll versions
MitsubishielectricGot2000 Gt2712-Stba FirmwareAll versions
MitsubishielectricGot2000 Gt2712-Stbd FirmwareAll versions
MitsubishielectricGot2000 Gt2715-Xtbd FirmwareAll versions
MitsubishielectricGot2000 Gt2715-Xtba FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-20601?
Improper input validation vulnerability in GOT2000 series GT27 model all versions, GOT2000 series GT25 model all versions, GOT2000 series GT23 model all versions, GOT2000 series GT21 model all versions, GOT SIMPLE series GS21 model all versions, and GT SoftGOT2000 all versions allows an remote unauthenticated attacker to write a value that exceeds the configured input range limit by sending a malicious packet to rewrite the device value. As a result, the system operation may be affected, such as malfunction.
How severe is CVE-2021-20601?
CVE-2021-20601 has a CVSS score of 7.5/10 (HIGH severity). The EPSS model estimates a 2.28% probability of exploitation in the next 30 days.
How do I fix CVE-2021-20601?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-20601?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST