First published: Tue Jan 29 2019(Updated: )
Mitsubishi Electric Q03/04/06/13/26UDVCPU: serial number 20081 and prior, Q04/06/13/26UDPVCPU: serial number 20081 and prior, and Q03UDECPU, Q04/06/10/13/20/26/50/100UDEHCPU: serial number 20101 and prior. A remote attacker can send specific bytes over Port 5007 that will result in an Ethernet stack crash.
Credit: ics-cert@hq.dhs.gov ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Mitsubishielectric Q03udvcpu Firmware | <=20081 | |
Mitsubishielectric Q03udvcpu | ||
Mitsubishielectric Q04udvcpu Firmware | <=20081 | |
Mitsubishielectric Q04udvcpu | ||
Mitsubishielectric Q06udvcpu Firmware | <=20081 | |
Mitsubishielectric Q06udvcpu | ||
Mitsubishielectric Q13udvcpu Firmware | <=20081 | |
Mitsubishielectric Q13udvcpu | ||
Mitsubishielectric Q26udvcpu Firmware | <=20081 | |
Mitsubishielectric Q26udvcpu | ||
Mitsubishielectric Q04udpvcpu Firmware | <=20081 | |
Mitsubishielectric Q04udpvcpu | ||
Mitsubishielectric Q06udpvcpu Firmware | <=20081 | |
Mitsubishielectric Q06udpvcpu | ||
Mitsubishielectric Q13udpvcpu Firmware | <=20081 | |
Mitsubishielectric Q13udpvcpu | ||
Mitsubishielectric Q26udpvcpu Firmware | <=20081 | |
Mitsubishielectric Q26udpvcpu | ||
Mitsubishielectric Q03udecpu Firmware | <=20101 | |
Mitsubishielectric Q03udecpu | ||
Mitsubishielectric Q04udehcpu Firmware | <=20101 | |
Mitsubishielectric Q04udehcpu | ||
Mitsubishielectric Q06udehcpu Firmware | <=20101 | |
Mitsubishielectric Q06udehcpu | ||
Mitsubishielectric Q10udehcpu Firmware | <=20101 | |
Mitsubishielectric Q10udehcpu | ||
Mitsubishielectric Q13udehcpu Firmware | <=20101 | |
Mitsubishielectric Q13udehcpu | ||
Mitsubishielectric Q20udehcpu Firmware | <=20101 | |
Mitsubishielectric Q20udehcpu | ||
Mitsubishielectric Q26udehcpu Firmware | <=20101 | |
Mitsubishielectric Q26udehcpu | ||
Mitsubishielectric Q50udehcpu Firmware | <=20101 | |
Mitsubishielectric Q50udehcpu | ||
Mitsubishielectric Q100udehcpu Firmware | <=20101 | |
Mitsubishielectric Q100udehcpu | ||
All of | ||
Mitsubishielectric Q03udvcpu Firmware | <=20081 | |
Mitsubishielectric Q03udvcpu | ||
All of | ||
Mitsubishielectric Q04udvcpu Firmware | <=20081 | |
Mitsubishielectric Q04udvcpu | ||
All of | ||
Mitsubishielectric Q06udvcpu Firmware | <=20081 | |
Mitsubishielectric Q06udvcpu | ||
All of | ||
Mitsubishielectric Q13udvcpu Firmware | <=20081 | |
Mitsubishielectric Q13udvcpu | ||
All of | ||
Mitsubishielectric Q26udvcpu Firmware | <=20081 | |
Mitsubishielectric Q26udvcpu | ||
All of | ||
Mitsubishielectric Q04udpvcpu Firmware | <=20081 | |
Mitsubishielectric Q04udpvcpu | ||
All of | ||
Mitsubishielectric Q06udpvcpu Firmware | <=20081 | |
Mitsubishielectric Q06udpvcpu | ||
All of | ||
Mitsubishielectric Q13udpvcpu Firmware | <=20081 | |
Mitsubishielectric Q13udpvcpu | ||
All of | ||
Mitsubishielectric Q26udpvcpu Firmware | <=20081 | |
Mitsubishielectric Q26udpvcpu | ||
All of | ||
Mitsubishielectric Q03udecpu Firmware | <=20101 | |
Mitsubishielectric Q03udecpu | ||
All of | ||
Mitsubishielectric Q04udehcpu Firmware | <=20101 | |
Mitsubishielectric Q04udehcpu | ||
All of | ||
Mitsubishielectric Q06udehcpu Firmware | <=20101 | |
Mitsubishielectric Q06udehcpu | ||
All of | ||
Mitsubishielectric Q10udehcpu Firmware | <=20101 | |
Mitsubishielectric Q10udehcpu | ||
All of | ||
Mitsubishielectric Q13udehcpu Firmware | <=20101 | |
Mitsubishielectric Q13udehcpu | ||
All of | ||
Mitsubishielectric Q20udehcpu Firmware | <=20101 | |
Mitsubishielectric Q20udehcpu | ||
All of | ||
Mitsubishielectric Q26udehcpu Firmware | <=20101 | |
Mitsubishielectric Q26udehcpu | ||
All of | ||
Mitsubishielectric Q50udehcpu Firmware | <=20101 | |
Mitsubishielectric Q50udehcpu | ||
All of | ||
Mitsubishielectric Q100udehcpu Firmware | <=20101 | |
Mitsubishielectric Q100udehcpu |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Mitsubishi Electric vulnerability is CVE-2019-6535.
CVE-2019-6535 has a severity level of 7.5 (high).
The affected software versions for CVE-2019-6535 are Q03/04/06/13/26UDVCPU: serial number 20081 and prior, Q04/06/13/26UDPVCPU: serial number 20081 and prior, Q03UDECPU, and Q04/06/10/13/20/26/50/100UDEHCPU: serial number 20101 and prior.
A remote attacker can exploit CVE-2019-6535 by sending specific bytes over Port 5007, which results in an Ethernet stack vulnerability.
You can find more information about CVE-2019-6535 on the following websites: securityfocus.com and ics-cert.us-cert.gov.