Mitsubishi Electric GOT2000 and GOT SIMPLE are vulnerable to a denial of service, caused by the use of predictable exact value from previous values in the FTP server function . By sending a specially crafted request, a remote attacker could exploit this vulnerability to cause a denial of service condition and perform spoofing attacks.
Mitsubishi Electric GT and GOT Series Products could allow a remote attacker to obtain sensitive information, caused by the use of weak encoding for password. By sniffing packets and utilize cryptographic attack techniques, an attacker could exploit this vulnerability to obtain plaintext passwords information, and use this information to launch further attacks against the affected system.
Upgrade to the latest version of GT and GOT Series Products, available from the Mitsubishi Electric Web site.