peter bassill · operator
$ cve CVE-2019-14927 JSON

CVE-2019-14927 EXPLOIT

7.5
HIGH · CVSS 3.1 · EPSS 41.8% (pctl 99)

Patch early

A public exploit exists.

Description

An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote configuration download vulnerability allows an attacker to download the smartRTU's configuration file (which contains data such as usernames, passwords, and other sensitive RTU data).

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS41.85% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-306
On CISA KEVno
Public exploityes
Published2019-10-28
Last modified2026-06-17

Affected (4)

VendorProduct
ineame-rtu
ineame-rtu firmware
mitsubishielectricsmartrtu
mitsubishielectricsmartrtu firmware

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD