CRITICAL
An issue was discovered on Mitsubishi Electric Europe B.V
Published Oct 28, 2019
9.8
CRITICALCVSS 3.1
EPSS 2.34%
Description
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Undocumented hard-coded user passwords for root, ineaadmin, mitsadmin, and maint could allow an attacker to gain unauthorised access to the RTU. (Also, the accounts ineaadmin and mitsadmin are able to escalate privileges to root without supplying a password due to insecure entries in /etc/sudoers on the RTU.)
Affected products
No data.
Configuration 1
AND
- ≤ 2.02
Running on/with
- n/a
Configuration 2
AND
- ≤ 3.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-6028 Advisory
- https://www.mogozobo.com/ Third Party Advisory
- https://www.mogozobo.com/?p=3593 ExploitThird Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-6028 | Advisory | |
| https://www.mogozobo.com/ | Third Party Advisory | |
| https://www.mogozobo.com/?p=3593 | ExploitThird Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Oct 28, 2019
Updated Sep 10, 2024
Reserved Aug 10, 2019
Link CVE-2019-14930
CISA Vulnrichment
Updated n/a
ENISA EUVD
EUVD-2019-6028 Assigner mitre
Published Oct 28, 2019
Updated Sep 10, 2024
Exploited since n/a
Link EUVD-2019-6028