First published: Thu May 23 2019(Updated: )
In Mitsubishi Electric MELSEC-Q series Ethernet module QJ71E71-100 serial number 20121 and prior, an attacker could send crafted TCP packets against the FTP service, forcing the target devices to enter an error mode and cause a denial-of-service condition.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Mitsubishielectric Qj71e71-100 Firmware | <=20121 | |
Mitsubishielectric Qj71e71-100 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10977 is a vulnerability in the Mitsubishi Electric MELSEC-Q series Ethernet module QJ71E71-100 that allows an attacker to cause a denial-of-service condition by sending crafted TCP packets against the FTP service.
CVE-2019-10977 has a severity value of 7.5 (high).
The affected software is Mitsubishi Electric MELSEC-Q series Ethernet module QJ71E71-100 with serial number 20121 and prior.
CVE-2019-10977 can be exploited by sending crafted TCP packets against the FTP service of the vulnerable device.
At the moment, there is no fix or mitigation available for CVE-2019-10977. It is advised to follow the recommendations provided by the vendor and update the software when a patch becomes available.