Description
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A world-readable /usr/smartrtu/init/settings.xml configuration file on the file system allows an attacker to read sensitive configuration settings such as usernames, passwords, and other sensitive RTU data due to insecure permission assignment.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-6023 | An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A world-readable /usr/smartrtu/init/settings.xml configuration file on the file system allows an attacker to read sensitive configuration settings such as usernames, passwords, and other sensitive RTU data due to insecure permission assignment. |
References
| Link | Providers |
|---|---|
| https://www.mogozobo.com/ |
|
| https://www.mogozobo.com/?p=3593 |
|
History
Tue, 10 Sep 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered on Mitsubishi Electric ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A world-readable /usr/smartrtu/init/settings.xml configuration file on the file system allows an attacker to read sensitive configuration settings such as usernames, passwords, and other sensitive RTU data due to insecure permission assignment. | An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A world-readable /usr/smartrtu/init/settings.xml configuration file on the file system allows an attacker to read sensitive configuration settings such as usernames, passwords, and other sensitive RTU data due to insecure permission assignment. |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-10T17:06:17.053Z
Reserved: 2019-08-10T00:00:00.000Z
Link: CVE-2019-14925
No data.
Status : Modified
Published: 2019-10-28T13:15:10.600
Modified: 2024-11-21T04:27:41.697
Link: CVE-2019-14925
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD