CVE-2023-3373
low-risk
Published 2023-08-04
Predictable Exact Value from Previous Values vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT21 model versions 01.49.000 and prior and GOT SIMPLE Series GS21 model versions 01.49.000 and prior allows a remote unauthenticated attacker to hijack data connections (session hijacking) or prevent legitimate users from establishing data connections (to cause DoS condition) by guessing the listening port of the data connection on FTP server and connecting to it.
Do I need to act?
-
0.48% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
5
CVSS 5.9/10
Medium
NETWORK
/ HIGH complexity
Affected Products (2)
Gt21 Firmware
Gs21 Firmware
Affected Vendors
References (6)
Third Party Advisory
https://jvn.jp/vu/JVNVU92167394/index.html
Third Party Advisory
https://www.cisa.gov/news-events/ics-advisories/icsa-23-215-01
Third Party Advisory
https://jvn.jp/vu/JVNVU92167394/index.html
Third Party Advisory
https://www.cisa.gov/news-events/ics-advisories/icsa-23-215-01
27
/ 100
low-risk
Severity
18/34 · Moderate
Exploitability
2/34 · Minimal
Exposure
7/34 · Low