CVE-2019-14925
28.10.2019, 13:15
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A world-readable /usr/smartrtu/init/settings.xml configuration file on the file system allows an attacker to read sensitive configuration settings such as usernames, passwords, and other sensitive RTU data due to insecure permission assignment.Enginsight
Vendor | Product | Version |
---|---|---|
mitsubishielectric | smartrtu_firmware | 𝑥 ≤ 2.02 |
inea | me-rtu_firmware | 𝑥 ≤ 3.0 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration