CVE & CISA-KEV Catalog

CVE-2023-0525

HIGH
7.5
CVSS v3
NVD

Description

Weak Encoding for Password vulnerability in Mitsubishi Electric Corporation GOT2000 Series GT27 model versions 01.49.000 and prior, GT25 model versions 01.49.000 and prior, GT23 model versions 01.49.000 and prior, GT21 model versions 01.49.000 and prior, GOT SIMPLE Series GS25 model versions 01.49.000 and prior, GS21 model versions 01.49.000 and prior, GT Designer3 Version1 (GOT2000) versions 1.295H and prior and GT SoftGOT2000 versions 1.295H and prior allows a remote unauthenticated attacker to obtain plaintext passwords by sniffing packets containing encrypted passwords and decrypting the encrypted passwords, in the case of transferring data with GT Designer3 Version1(GOT2000) and GOT2000 Series or GOT SIMPLE Series with the Data Transfer Security function enabled, or in the case of transferring data by the SoftGOT-GOT link function with GT SoftGOT2000 and GOT2000 series with the Data Transfer Security function enabled.

How to fix

Remediation Available
gs21 firmwareNVD
Affected:< 01.50.000Fixed in:01.50.000CVE-2023-0525derived from NVD
gs25 firmwareNVD
Affected:< 01.50.000Fixed in:01.50.000CVE-2023-0525derived from NVD
gt21 firmwareNVD
Affected:< 01.50.000Fixed in:01.50.000CVE-2023-0525derived from NVD
gt23 firmwareNVD
Affected:< 01.50.000Fixed in:01.50.000CVE-2023-0525derived from NVD
gt25 firmwareNVD
Affected:< 01.50.000Fixed in:01.50.000CVE-2023-0525derived from NVD
gt27 firmwareNVD
Affected:< 01.50.000Fixed in:01.50.000CVE-2023-0525derived from NVD
gt designer3NVD
Affected:< 1.300nFixed in:1.300nCVE-2023-0525derived from NVD
gt softgot2000NVD
Affected:< 1.300nFixed in:1.300nCVE-2023-0525derived from NVD

Remediation is compiled from vendor and distribution security advisories. Always confirm against the linked source for your exact version and platform.

CVSS v3 Vector

Exploitability

Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged

Impact

ConfidentialityHigh
IntegrityNone
AvailabilityNone

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Exploit Intelligence

0.48%probability of exploitation in 30 days
38thpercentile

Low risk: more likely to be exploited than 38% of all known CVEs.

References

Vendor Advisory1
Third-Party Advisory2
Embed a live status badge for CVE-2023-0525
CVE-2023-0525 severity badge

Markdown

[![CVE-2023-0525](https://tridentstack.com/cve/badge/CVE-2023-0525.svg)](https://tridentstack.com/cve/CVE-2023-0525)

HTML

<a href="https://tridentstack.com/cve/CVE-2023-0525"><img src="https://tridentstack.com/cve/badge/CVE-2023-0525.svg" alt="CVE-2023-0525"></a>

Find and fix vulnerabilities across your fleet

TridentStack Control continuously scans your Windows, macOS, and Linux fleet for known vulnerabilities, prioritizes them by severity and active exploitation, and patches them automatically.

Start free

This product uses NVD data but is not endorsed or certified by the NVD. EPSS scores courtesy of FIRST.org (https://www.first.org/epss). Source: CISA KEV Catalog. Data as of 2024-11-21.