LiveActive security incident?Get immediate response
CVE Record

CVE-2020-5648: Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in TCP/IP...

Improper neutralization of argument delimiters in a command ('Argument Injection') vulnerability in TCP/IP function included in the firmware of GT14 Model of GOT 1000 series (GT1455-QTBDE CoreOS version "05.65.00.BD" and earlier, GT1450-QMBDE CoreOS version "05.65.00.BD" and earlier, GT1450-QLBDE CoreOS version "05.65.00.BD" and earlier, GT1455HS-QTBDE CoreOS version "05.65.00.BD" and earlier, and GT1450HS-QMBDE CoreOS version "05.65.00.BD" and earlier) allows unauthenticated attackers on adjacent network to stop the network functions of the products via a specially crafted packet.

UnknownCVSS not scoredNot KEV-listedUpdated
Glexia's TakeAutomated analysismoderate

Security readout for executives and security teams

Plain-English summary

This flaw can let an unauthenticated attacker already on a nearby network disrupt network functions on specific Mitsubishi Electric GT14 GOT1000 operator terminals. The main business risk is loss of HMI communications or operational visibility, not confirmed data theft or system takeover.

Executive priority

Treat as an OT availability risk. Prioritize sites where affected terminals support critical operations or share network segments with unmanaged devices. Validate exposure before emergency action because severity, CVSS, and exploit activity are not provided.

Technical view

CVE-2020-5648 is an argument injection issue in the TCP/IP function of affected GT14 GOT1000 firmware. Listed GT1455/GT1450 models running CoreOS 05.65.00.BD or earlier can have network functions stopped by a specially crafted packet from an adjacent network.

Likely exposure

Exposure is limited to organizations using the named Mitsubishi Electric GT14 GOT1000 models on networks reachable by adjacent devices. The provided sources do not support internet-wide exposure or impact to other GOT series models.

Exploitation context

CISA KEV status is false, and the bundle provides no evidence of active exploitation. The attacker does not need authentication, but must be on an adjacent network. The stated outcome is stopping product network functions.

Researcher notes

The bundle names argument injection in TCP/IP handling and adjacent-network unauthenticated access, but does not include CVSS, CWE, packet details, or fixed firmware version. Avoid assuming broader product impact beyond the listed GT14 models.

Mitigation direction

  • Identify affected GT14 GOT1000 models and CoreOS versions.
  • Review Mitsubishi Electric advisory 2020-014 for official fixes or mitigations.
  • Restrict untrusted adjacent network access to affected HMIs.
  • Segment OT networks and limit management-plane reachability.
  • Monitor affected segments for unexpected HMI communication loss.

Validation and detection

  • Inventory GT14 GOT1000 terminals by exact model and CoreOS version.
  • Confirm whether any listed model runs CoreOS 05.65.00.BD or earlier.
  • Map which devices can reach affected terminals on adjacent networks.
  • Check vendor advisory status before planning firmware changes.
  • Review logs or operations records for unexplained network-function stoppages.
Prepared
Confidence
medium
Sources
5

Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.

Potential ATT&CK relevance

Conservative CVE-to-ATT&CK context

These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.

ATT&CK lookup starting points

Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.

cve · low confidence lookup

CVE-2020-5648 mapping review

Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.

Open ATT&CK lookup
Vulnerability profileCVE Program record
Severity
Unknown
CVSS
Not scored
Known Exploited
No
Published
Official CVE source material

CNA and ADP enrichment extracted from CVE v5

These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.

0CVSS vectors
0Timeline events
0ADP providers
5Source links

CVSS and timeline data

No CVSS vectors or timeline events were available in the normalized CVE source material.

Affected products

Products and packages named in the record

VendorProductVersion / packageStatus
Mitsubishi Electric CorporationGT14 Model of GOT 1000 series(GT1455-QTBDE CoreOS version ’05.65.00.BD’ and earlier, GT1450-QMBDE CoreOS version ’05.65.00.BD’ and earlier, GT1450-QLBDE CoreOS version ’05.65.00.BD’ and earlier, GT1455HS-QTBDE CoreOS version ’05.65.00.BD’ and earlier, and GT1450HS-QMBDE CoreOS version ’05.65.00.BD’ and earlier)Listed
Weakness

CWE details

No CWE listed

CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.