CVE-2020-5599
Description
TCP/IP function included in the firmware of Mitsubishi Electric GOT2000 series (CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model) contains an improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability, which may allow a remote attacker to stop the network functions of the products or execute a malicious program via a specially crafted packet.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An argument injection vulnerability (CWE-88) in the TCP/IP stack of Mitsubishi Electric GOT2000 series allows remote attackers to stop network functions or execute arbitrary code.
Vulnerability
The TCP/IP function in CoreOS versions -Y and earlier on Mitsubishi Electric GOT2000 series (GT27, GT25, and GT23 models) contains an improper neutralization of argument delimiters in a command vulnerability (CWE-88), also categorized as an argument injection [1]. The affected firmware versions are those prior to version Z [1]. The vulnerability exists in the network stack's parsing of specially crafted packets, allowing manipulation of command arguments without proper sanitization [1].
Exploitation
An attacker requires network connectivity to the target device and the ability to send a specially crafted packet [1]. No authentication is mentioned as a prerequisite; the attack can be launched remotely over a network [1]. By crafting the packet with malicious argument delimiters, the attacker can inject additional commands into the TCP/IP processing logic [1]. The steps involve sending the malicious packet to the target GOT2000 series HMI unit [1].
Impact
Successful exploitation can lead to either a denial of service (stopping network functions) or arbitrary code execution (running a malicious program) on the affected device [1]. The attacker may achieve full compromise of the network functionality or execute arbitrary commands in the context of the affected TCP/IP stack [1]. This could disrupt industrial control operations or allow further lateral movement within the network [1].
Mitigation
The official solution is to update CoreOS to version Z or later [1]. This requires installing MELSOFT GT Designer3(2000) version 1.240A, creating CoreOS with version Z on an SD card, and updating the affected product [1]. As a workaround, restricting access from untrusted networks or hosts can reduce the attack surface [1]. No other mitigations beyond vendor-provided updates and network access controls are documented in the references [1].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2CoreOS version -Y and earlier+ 1 more
- (no CPE)range: CoreOS version -Y and earlier
- (no CPE)range: CoreOS with version -Y and earlier installed in GT27 Model, GT25 Model, and GT23 Model
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- jvn.jp/en/vu/JVNVU95413676/index.htmlmitrex_refsource_MISC
- www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-005_en.pdfmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.