Rewterz Threat Alert – Earth Preta aka Mustang Panda APT Group – Active IOCs
August 4, 2023Rewterz Threat Advisory – CVE-2023-4104 – Mozilla VPN Vulnerability
August 4, 2023Rewterz Threat Alert – Earth Preta aka Mustang Panda APT Group – Active IOCs
August 4, 2023Rewterz Threat Advisory – CVE-2023-4104 – Mozilla VPN Vulnerability
August 4, 2023Severity
Medium
Analysis Summary
CVE-2023-3373 CVSS:5.9
Mitsubishi Electric GOT2000 and GOT SIMPLE are vulnerable to a denial of service, caused by the use of predictable exact value from previous values in the FTP server function . By sending a specially crafted request, a remote attacker could exploit this vulnerability to cause a denial of service condition and perform spoofing attacks.
CVE-2023-0525 CVSS:7.5
Mitsubishi Electric GT and GOT Series Products could allow a remote attacker to obtain sensitive information, caused by the use of weak encoding for password. By sniffing packets and utilize cryptographic attack techniques, an attacker could exploit this vulnerability to obtain plaintext passwords information, and use this information to launch further attacks against the affected system.
Impact
- Denial of Service
- Information Disclosure
Indicators Of Compromise
CVE
- CVE-2023-3373
- CVE-2023-0525
Affected Vendors
Mitsubishi Electric
Affected Products
- Mitsubishi Electric GOT2000 01.49.000
- Mitsubishi Electric GOT SIMPLE 01.49.000
- Mitsubishi Electric GT Designer3 Version1 (GOT2000) 1.295H
- Mitsubishi Electric SoftGOT2000 1.295H
Remediation
Upgrade to the latest version of GT and GOT Series Products, available from the Mitsubishi Electric Web site.