Buffer overflow vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT1455-QTBDE CoreOS version "05.65.00.BD" and earlier, GT1450-QMBDE CoreOS version "05.65.00.BD" and earlier, GT1450-QLBDE CoreOS version "05.65.00.BD" and earlier, GT1455HS-QTBDE CoreOS version "05.65.00.BD" and earlier, and GT1450HS-QMBDE CoreOS version "05.65.00.BD" and earlier) allows a remote unauthenticated attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.
Link | Tags |
---|---|
https://us-cert.cisa.gov/ics/advisories/icsa-20-310-02 | third party advisory us government resource |
https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-014_en.pdf | vendor advisory |
https://www.mitsubishielectric.co.jp/psirt/vulnerability/pdf/2020-014.pdf | vendor advisory |
https://jvn.jp/vu/JVNVU99562395/index.html | third party advisory |