Security readout for executives and security teams
Plain-English summary
Certain Mitsubishi Electric GT14 GOT 1000 operator panels can have their network functions stopped by an unauthenticated remote attacker. For industrial environments, the main risk is loss of HMI network connectivity, which can disrupt monitoring or operations. The provided sources do not show active exploitation or a CVSS score.
Executive priority
Treat this as an OT availability risk. Prioritize sites where affected HMIs support production, safety monitoring, or remote operations, especially if reachable beyond a tightly controlled control network.
Technical view
CVE-2020-5645 is a session fixation vulnerability in the TCP/IP function of specified GT14 GOT 1000 firmware. Affected CoreOS versions are 05.65.00.BD and earlier for the listed GT1455, GT1450, and handheld variants. The reported impact is remote unauthenticated denial of network functions using a crafted packet.
Likely exposure
Exposure is limited to organizations using the listed Mitsubishi Electric GT14 GOT 1000 models with affected CoreOS versions and reachable TCP/IP services. Internet exposure is not stated in the sources; assess OT network reachability directly.
Exploitation context
The source bundle states remote unauthenticated attack capability, but provides no public exploit status. CISA KEV is false, and no cited source in the bundle supports active exploitation.
Researcher notes
Evidence is sufficient for affected model and version scoping, attack preconditions, and impact class. The bundle lacks CVSS, CWE, detailed protocol context, fixed-version text, and exploitation evidence, so avoid stronger claims without checking the vendor advisory.
Mitigation direction
- Check Mitsubishi Electric PSIRT 2020-014 for official remediation guidance.
- Update affected GT14 CoreOS firmware if vendor guidance provides a fixed version.
- Restrict network access to GOT devices to trusted OT hosts only.
- Place HMI networks behind firewalls and isolate them from corporate networks.
- Monitor affected devices for unexpected loss of network functions.
Validation and detection
- Inventory GT14 GOT 1000 models in the environment.
- Confirm each device model against the affected product list.
- Check CoreOS version and flag 05.65.00.BD or earlier.
- Review firewall rules for remote reachability to GOT TCP/IP services.
- Document any compensating segmentation or vendor remediation applied.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2020-5645 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://us-cert.cisa.gov/ics/advisories/icsa-20-310-02CVE reference · x_refsource_MISC
- https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-014_en.pdfCVE reference · x_refsource_MISC
- https://www.mitsubishielectric.co.jp/psirt/vulnerability/pdf/2020-014.pdfCVE reference · x_refsource_MISC
- https://jvn.jp/vu/JVNVU99562395/index.htmlCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
