← Back to home
ICSA-22-319-01  ·  Published 2022-11-15  ·  View on CISA ICS-CERT ↗

Mitsubishi Electric GT SoftGOT2000

CVSS 9.8 CRITICAL

Risk Summary

Successful exploitation of this vulnerability could allow an attacker to execute malicious OS commands.

CVEs (1)

Remediations

  • Mitsubishi Electric recommends users install version 1.285X or later to mitigate this issue. Users should contact Mitsubishi Electric to obtain the fixed version of GT SoftGOT2000. For detailed installation procedures, users should refer to "GT SoftGOT2000 Version1 Operation Manual (SH-081201ENG)."
  • Refer to the Mitsubishi Electric advisory for further details and instructions for determining installed versions.
  • Use affected products from inside a local area network (LAN) and block access from untrusted networks and hosts.
  • Install antivirus software on the host machine where affected products are installed.
  • Restrict physical access to the host machine with the products installed and network equipment.
  • Do not store untrusted certificates.
  • Do not click on web links in emails or any other communications from untrusted sources.

Affected Vendors

Mitsubishi Electric

Affected Products (1)

Mitsubishi Electric · GT SoftGOT2000 1.275M—1.280S

Affected Sectors

Critical Manufacturing

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more