CVE-2019-10977: High severity mitsubishi electric qj71e71-100 firmware vulnerability
In Mitsubishi Electric MELSEC-Q series Ethernet module QJ71E71-100 serial number 20121 and prior, an attacker could send crafted TCP packets against the FTP service, forcing the target devices to enter an error mode and cause a denial-of-service condition.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-10977?
CVE-2019-10977 is a vulnerability in the Mitsubishi Electric MELSEC-Q series Ethernet module QJ71E71-100 that allows an attacker to cause a denial-of-service condition by sending crafted TCP packets against the FTP service.
How severe is CVE-2019-10977?
CVE-2019-10977 has a severity value of 7.5 (high).
What software is affected by CVE-2019-10977?
The affected software is Mitsubishi Electric MELSEC-Q series Ethernet module QJ71E71-100 with serial number 20121 and prior.
How can CVE-2019-10977 be exploited?
CVE-2019-10977 can be exploited by sending crafted TCP packets against the FTP service of the vulnerable device.
Are there any fix or mitigation measures for CVE-2019-10977?
At the moment, there is no fix or mitigation available for CVE-2019-10977. It is advised to follow the recommendations provided by the vendor and update the software when a patch becomes available.