CVE-2021-20590

Improper authentication vulnerability in GOT2000 series GT27 model VNC server versions 01.39.010 and prior, GOT2000 series GT25 model VNC server versions 01.39.010 and prior, GOT2000 series GT21 model GT2107-WTBD VNC server versions 01.40.000 and prior, GOT2000 series GT21 model GT2107-WTSD VNC server versions 01.40.000 and prior, GOT SIMPLE series GS21 model GS2110-WTBD-N VNC server versions 01.40.000 and prior and GOT SIMPLE series GS21 model GS2107-WTBD-N VNC server versions 01.40.000 and prior allows a remote unauthenticated attacker to gain unauthorized access via specially crafted packets when the "VNC server" function is used.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
MitsubishiCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 49%
VendorProductVersion
mitsubishielectricgot2000_gt27_firmware
𝑥
≤ 01.39.010
mitsubishielectricgot2000_gt25_firmware
𝑥
≤ 01.39.010
mitsubishielectricgt2107-wtbd_firmware
𝑥
≤ 01.40.000
mitsubishielectricgt2107-wtsd_firmware
𝑥
≤ 01.40.000
mitsubishielectricgs2110-wtbd-n_firmware
𝑥
≤ 01.40.000
mitsubishielectricgs2107-wtbd-n_firmware
𝑥
≤ 01.40.000
𝑥
= Vulnerable software versions