CVE-2018-16060: High severity mitsubishielectric smartrtu firmware vulnerability
Mitsubishi Electric Europe B.V. SmartRTU devices allow remote attackers to obtain sensitive information (directory listing and source code) via a direct request to the /web URI.
Other sources
Mitsubishi Electric SmartRTU devices allow remote attackers to obtain sensitive information (directory listing and source code) via a direct request to the /web URI.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Mitsubishi Electric SmartRTU vulnerability?
The vulnerability ID for this Mitsubishi Electric SmartRTU vulnerability is CVE-2018-16060.
What is the severity rating of CVE-2018-16060?
CVE-2018-16060 has a severity rating of 7.5 (high).
How can remote attackers exploit CVE-2018-16060?
Remote attackers can exploit CVE-2018-16060 by making a direct request to the /web URI to obtain sensitive information, such as directory listings and source code.
What is the affected software for CVE-2018-16060?
The affected software for CVE-2018-16060 is Mitsubishi Electric SmartRTU firmware.
Are Mitsubishi Electric SmartRTU devices vulnerable to CVE-2018-16060?
Yes, Mitsubishi Electric SmartRTU devices are vulnerable to CVE-2018-16060.
How can I fix CVE-2018-16060?
To fix CVE-2018-16060, it is recommended to apply any available patches or firmware updates provided by Mitsubishi Electric.
Where can I find more information about CVE-2018-16060?
You can find more information about CVE-2018-16060 at the following references: [Link 1](http://packetstormsecurity.com/files/164538/Mitsubishi-Electric-INEA-SmartRTU-Source-Code-Disclosure.html), [Link 2](https://drive.google.com/open?id=1QMHwTnBbIqrTkR0NEpnTKssYdi8vRsHH).