7.5
CVSSv3

CVE-2019-14927

Published: 28/10/2019 Updated: 21/07/2021
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

An issue exists on Mitsubishi Electric ME-RTU devices up to and including 2.02 and INEA ME-RTU devices up to and including 3.0. An unauthenticated remote configuration download vulnerability allows an malicious user to download the smartRTU's configuration file (which contains data such as usernames, passwords, and other sensitive RTU data).

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mitsubishielectric smartrtu firmware

inea me-rtu firmware

Vendor Advisories

Check Point Reference: CPAI-2019-3126 Date Published: 11 Dec 2023 Severity: High ...

Exploits

#!/usr/bin/python # Exploit Title: Mitsubishi Electric smartRTU & INEA ME-RTU Unauthenticated Configuration Download # Date: 29 June 2019 # Exploit Author: (@xerubus | mogozobocom) # Vendor Homepage: eu3amitsubishielectriccom/fa/en/products/cnt/plcccl/items/smartRTU/local # Vendor Homepage: wwwineasi/en/telemetrija-in-m2m- ...