Improper authentication vulnerability in GOT2000 series GT27 model VNC server versions 01.39.010 and prior, GOT2000 series GT25 model VNC server versions 01.39.010 and prior, GOT2000 series GT21 model GT2107-WTBD VNC server versions 01.40.000 and prior, GOT2000 series GT21 model GT2107-WTSD VNC server versions 01.40.000 and prior, GOT SIMPLE series GS21 model GS2110-WTBD-N VNC server versions 01.40.000 and prior and GOT SIMPLE series GS21 model GS2107-WTBD-N VNC server versions 01.40.000 and prior allows a remote unauthenticated attacker to gain unauthorized access via specially crafted packets when the "VNC server" function is used.
References
Link | Resource |
---|---|
https://jvn.jp/vu/JVNVU97615777/index.html | Mitigation Third Party Advisory |
https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2021-001_en.pdf | Mitigation Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Configuration 6 (hide)
AND |
|
Information
Published : 2021-04-22 12:15
Updated : 2022-05-12 13:15
NVD link : CVE-2021-20590
Mitre link : CVE-2021-20590
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
mitsubishielectric
- gt2107-wtsd_firmware
- gs2107-wtbd-n_firmware
- gt2107-wtsd
- gt2107-wtbd_firmware
- got2000_gt27
- got2000_gt27_firmware
- got2000_gt25_firmware
- gs2107-wtbd-n
- gs2110-wtbd-n_firmware
- got2000_gt25
- gs2110-wtbd-n
- gt2107-wtbd