9.8
CVSSv3

CVE-2019-14930

Published: 28/10/2019 Updated: 30/10/2019
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

An issue exists on Mitsubishi Electric ME-RTU devices up to and including 2.02 and INEA ME-RTU devices up to and including 3.0. Undocumented hard-coded user passwords for root, ineaadmin, mitsadmin, and maint could allow an malicious user to gain unauthorised access to the RTU. (Also, the accounts ineaadmin and mitsadmin are able to escalate privileges to root without supplying a password due to insecure entries in /etc/sudoers on the RTU.)

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mitsubishielectric smartrtu firmware

inea me-rtu firmware