CVE-2020-5543
TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier does not properly manage sessions, which allows remote attackers to stop the network functions or execute malware via a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.21%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier does not properly manage sessions, which allows remote attackers to stop the network functions or execute malware via a specially crafted packet.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.21% probability · 82th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-384
- Affected
- mitsubishielectric/iu1-1m20-d firmware
- Source
- vultures@jpcert.or.jp
References
- https://jvn.jp/en/vu/JVNVU92370624/index.htmlThird Party Advisory
- https://www.mitsubishielectric.co.jp/psirt/vulnerability/pdf/2019-004.pdfPatch, Vendor Advisory
- https://jvn.jp/en/vu/JVNVU92370624/index.htmlThird Party Advisory
- https://www.mitsubishielectric.co.jp/psirt/vulnerability/pdf/2019-004.pdfPatch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.