Security readout for executives and security teams
Plain-English summary
This flaw can let an unauthenticated remote attacker disrupt network functions on specific Mitsubishi Electric GOT 1000 GT14 operator terminals. For an industrial site, the concern is loss of HMI network availability, not confirmed data theft or code execution from the provided sources.
Executive priority
Treat as a targeted operational availability risk for industrial environments using the named Mitsubishi HMI models. Prioritize inventory and vendor-guidance review, especially where devices bridge production networks or remote access paths.
Technical view
CVE-2020-5646 is a NULL pointer dereference in a TCP/IP function in firmware for listed GT14 GOT 1000 models running CoreOS 05.65.00.BD or earlier. A specially crafted packet can stop product network functions. No CVSS, CWE, public exploit confirmation, or patch detail is provided in the bundle.
Likely exposure
Exposure is most relevant where affected GT14 GOT 1000 terminals can receive network traffic from untrusted or insufficiently segmented networks. Impact appears availability-focused: stopped network functions on the device.
Exploitation context
The source bundle says remote unauthenticated exploitation is possible via a specially crafted packet. It does not show active exploitation, KEV listing, exploit maturity, internet scanning, or weaponized public exploit evidence.
Researcher notes
The evidence supports unauthenticated remote denial of network functions, but not code execution, persistence, or confirmed exploitation. Missing CVSS and remediation details limit precision. Validate exposure by model, CoreOS version, and reachable network paths.
Mitigation direction
- Identify affected Mitsubishi GOT 1000 GT14 models in asset inventory.
- Check each device CoreOS version against 05.65.00.BD and earlier.
- Review Mitsubishi Electric PSIRT advisory 2020-014 for vendor-supported fixes or workarounds.
- Review CISA ICSA-20-310-02 for operational mitigation guidance.
- Reduce untrusted network reachability to affected devices pending vendor guidance.
Validation and detection
- Confirm model numbers: GT1455-QTBDE, GT1450-QMBDE, GT1450-QLBDE, GT1455HS-QTBDE, or GT1450HS-QMBDE.
- Record CoreOS versions from device management or maintenance records.
- Map which networks can send traffic to affected GOT terminals.
- Check logs or operator reports for unexpected loss of device network functions.
- Document whether vendor advisory guidance has been applied.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2020-5646 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://us-cert.cisa.gov/ics/advisories/icsa-20-310-02CVE reference · x_refsource_MISC
- https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2020-014_en.pdfCVE reference · x_refsource_MISC
- https://www.mitsubishielectric.co.jp/psirt/vulnerability/pdf/2020-014.pdfCVE reference · x_refsource_MISC
- https://jvn.jp/vu/JVNVU99562395/index.htmlCVE reference · x_refsource_MISC
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
