Security Advisory

CVE-2020-5648

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-11-06 02:06:30
Last updated 2024-08-04 08:39:25
Assigner jpcert
State PUBLISHED

Description

Improper neutralization of argument delimiters in a command (Argument Injection) vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT1455-QTBDE CoreOS version "05.65.00.BD" and earlier, GT1450-QMBDE CoreOS version "05.65.00.BD" and earlier, GT1450-QLBDE CoreOS version "05.65.00.BD" and earlier, GT1455HS-QTBDE CoreOS version "05.65.00.BD" and earlier, and GT1450HS-QMBDE CoreOS version "05.65.00.BD" and earlier) allows unauthenticated attackers on adjacent network to stop the network functions of the products via a specially crafted packet.