vendor:
smartRTU & INEA ME-RTU
by:
@xerubus
9.8
CVSS
CRITICAL
OS Command Injection
78
CWE
Product Name: smartRTU & INEA ME-RTU
Affected Version From: Misubishi Electric 2.02 & INEA 3.0
Affected Version To: Misubishi Electric 2.02 & INEA 3.0
Patch Exists: YES
Related CWE: CVE-2019-14931
CPE: h:mitsubishi_electric:smartrtu
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: None
2019
Mitsubishi Electric smartRTU & INEA ME-RTU Unauthenticated OS Command Injection
Mitsubishi Electric smartRTU & INEA ME-RTU are vulnerable to unauthenticated OS command injection. An attacker can send a specially crafted HTTP POST request to the vulnerable device to execute arbitrary OS commands. This vulnerability can be exploited without authentication.
Mitigation:
The vendor has released a patch to address this vulnerability. Users should update their devices to the latest version.