CISA issued advisories for multiple vulnerabilities in Mitsubishi Electric GOT2000 and GOT SIMPLE human-machine interfaces that affect the devices' built-in FTP server function. One flaw, CVE-2022-40266, is an improper input validation issue in GOT2000 Series GT27, GT25, and GT23 models that can let an authenticated low-privilege attacker send a specially crafted command and trigger a denial-of-service condition. A second flaw, CVE-2023-3373 (CWE-342), affects GOT2000 Series GT21 and GOT SIMPLE GS21 devices, where predictable FTP data connection port values could enable denial of service or spoofing through session hijacking.
Mitsubishi Electric said affected FTP server versions include 01.39.000 and earlier for the first issue and 01.49.000 and earlier for the second, with fixes available in 01.47.000+ and 01.50.000+ respectively. CISA reported both vulnerabilities as remotely exploitable with no known public exploits and urged operators to update affected systems, disable the FTP server function if it is unnecessary, and apply industrial control system hardening measures such as isolating control networks, blocking untrusted access, using VPNs for remote connectivity, enforcing IP filtering, and avoiding direct Internet exposure.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
CISA released ICS advisory ICSA-23-215-01 for CVE-2023-3373, a remotely exploitable FTP server weakness in Mitsubishi Electric GOT2000 and GOT SIMPLE products. The advisory noted no known public exploits and recommended upgrading, restricting access, and disabling FTP if unnecessary.
Mitsubishi Electric addressed a predictable FTP data connection port vulnerability affecting GOT2000 Series GT21 and GOT SIMPLE GS21 devices, which could enable denial of service or spoofing via session hijacking. The issue affected version 01.49.000 and earlier, with version 01.50.000 or later listed as fixed.
CISA issued ICS advisory ICSA-22-333-01 covering CVE-2022-40266 in Mitsubishi Electric GOT2000 Series devices. The advisory said the vulnerability was remotely exploitable, affected availability, and had no known public exploits at the time of publication.
Mitsubishi Electric identified an improper input validation flaw in the GOT2000 Series FTP server affecting GT27, GT25, and GT23 models, where an authenticated low-privilege attacker could trigger a denial of service with a crafted command. The company advised updating affected FTP server software from version 01.39.000 and earlier to version 01.47.000 or later.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
cisa.gov
Open sourcecisa.gov
Open sourcemitsubishielectric.com
Open sourcemitsubishielectric.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.