CVE-2019-14927
Summary
| CVE | CVE-2019-14927 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-10-28 13:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | An issue was discovered on Mitsubishi Electric ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote configuration download vulnerability allows an attacker to download the smartRTU's configuration file (which contains data such as usernames, passwords, and other sensitive RTU data). |
Risk And Classification
Problem Types: CWE-306 | CWE-425
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Inea | Me-rtu | - | All | All | All |
| Hardware | Inea | Me-rtu | - | All | All | All |
| Operating System | Inea | Me-rtu Firmware | All | All | All | All |
| Hardware | Mitsubishielectric | Smartrtu | - | All | All | All |
| Hardware | Mitsubishielectric | Smartrtu | - | All | All | All |
| Operating System | Mitsubishielectric | Smartrtu Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Mogozobo | MISC | www.mogozobo.com | Third Party Advisory |
| Mogozobo » (CVE-2019-14925 –> CVE-2019-14931) Mitsubishi Electric & INEA RTU Multiple Vulnerabilities | MISC | www.mogozobo.com | Exploit, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
Legacy QID Mappings
- 590908 Mitsubishi Electric Europe B.V. smartRTU and INEA ME-RTU Multiple Vulnerabilities (ICSA-21-252-03)