PoC Index

CVE-2019-14927

HIGH 7.5EPSS 41.8%

An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote configuration download vulnerability allows an attacker to download the smartRTU's configuration file (which contains data such as usernames, passwords, and other sensitive RTU data).

CVSS v3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
EPSS
41.85% chance of exploitation in the next 30 days, 99th percentile
Published
2019-10-28
Updated
2024-09-10

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related