Vulnerability Description
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware version 1.0.7 and earlier allows an attacker on the same network segment to stop the network functions or execute malware via a specially crafted packet.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mitsubishielectric | Iu1-1M20-D Firmware | <= 1.0.7 |
| Mitsubishielectric | Iu1-1M20-D | - |
Related Weaknesses (CWE)
References
- https://jvn.jp/en/vu/JVNVU92370624/index.htmlThird Party Advisory
- https://www.mitsubishielectric.co.jp/psirt/vulnerability/pdf/2019-004.pdfPatchVendor Advisory
- https://jvn.jp/en/vu/JVNVU92370624/index.htmlThird Party Advisory
- https://www.mitsubishielectric.co.jp/psirt/vulnerability/pdf/2019-004.pdfPatchVendor Advisory
FAQ
What is CVE-2020-5546?
CVE-2020-5546 is a vulnerability with a CVSS score of 8.8 (HIGH). Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in TCP function included in the firmware of Mitsubishi Electric MELQIC IU1 series IU1-1M20-D firmware v...
How severe is CVE-2020-5546?
CVE-2020-5546 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-5546?
Check the references section above for vendor advisories and patch information. Affected products include: Mitsubishielectric Iu1-1M20-D Firmware, Mitsubishielectric Iu1-1M20-D.