Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-14927

Опубликовано: 28 окт. 2019
Источник: nvd
CVSS3: 7.5
CVSS2: 5
EPSS Средний

Описание

An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote configuration download vulnerability allows an attacker to download the smartRTU's configuration file (which contains data such as usernames, passwords, and other sensitive RTU data).

Ссылки

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:mitsubishielectric:smartrtu_firmware:*:*:*:*:*:*:*:*
Версия до 2.02 (включая)
cpe:2.3:h:mitsubishielectric:smartrtu:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:inea:me-rtu_firmware:*:*:*:*:*:*:*:*
Версия до 3.0 (включая)
cpe:2.3:h:inea:me-rtu:-:*:*:*:*:*:*:*

EPSS

Процентиль: 96%
0.25332
Средний

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 7.5
github
больше 3 лет назад

An issue was discovered on Mitsubishi Electric ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote configuration download vulnerability allows an attacker to download the smartRTU's configuration file (which contains data such as usernames, passwords, and other sensitive RTU data).

EPSS

Процентиль: 96%
0.25332
Средний

7.5 High

CVSS3

5 Medium

CVSS2

Дефекты

CWE-306