CVE-2019-14927 EXPLOIT
7.5
HIGH · CVSS 3.1 · EPSS 41.8% (pctl 99)
Patch early
A public exploit exists.
Description
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote configuration download vulnerability allows an attacker to download the smartRTU's configuration file (which contains data such as usernames, passwords, and other sensitive RTU data).
Scoring
| CVSS | 7.5 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 41.85% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-306 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2019-10-28 |
| Last modified | 2026-06-17 |
Affected (4)
| Vendor | Product |
|---|---|
| inea | me-rtu |
| inea | me-rtu firmware |
| mitsubishielectric | smartrtu |
| mitsubishielectric | smartrtu firmware |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Mitsubishi Electric smartRTU / INEA ME-RTU - Unauthenticated Configuration Download | 2019-08-12 |
References
→ the Explorer · watch your stack · NVD