CVE-2019-14929: Critical severity mitsubishielectric smartrtu firmware vulnerability
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Stored cleartext passwords could allow an unauthenticated attacker to obtain configured username and password combinations on the RTU due to the weak credentials management on the RTU. An unauthenticated user can obtain the exposed password credentials to gain access to the following services: DDNS service, Mobile Network Provider, and OpenVPN service.
Other sources
An issue was discovered on Mitsubishi Electric ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Stored cleartext passwords could allow an unauthenticated attacker to obtain configured username and password combinations on the RTU due to the weak credentials management on the RTU. An unauthenticated user can obtain the exposed password credentials to gain access to the following services: DDNS service, Mobile Network Provider, and OpenVPN service.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-14929?
CVE-2019-14929 is a vulnerability that affects Mitsubishi Electric ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. It allows an unauthenticated attacker to obtain configured username and password combinations due to weak credentials management.
How severe is CVE-2019-14929?
CVE-2019-14929 has a severity rating of 9.8, which is considered critical.
Which Mitsubishi Electric ME-RTU devices are affected by CVE-2019-14929?
CVE-2019-14929 affects Mitsubishi Electric ME-RTU devices through version 2.02.
Which INEA ME-RTU devices are affected by CVE-2019-14929?
CVE-2019-14929 affects INEA ME-RTU devices through version 3.0.
How do I mitigate CVE-2019-14929?
To mitigate CVE-2019-14929, it is recommended to implement strong credentials management on the affected devices.