Description
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A world-readable /usr/smartrtu/init/settings.xml configuration file on the file system allows an attacker to read sensitive configuration settings such as usernames, passwords, and other sensitive RTU data due to insecure permission assignment.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2019-6023 | An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A world-readable /usr/smartrtu/init/settings.xml configuration file on the file system allows an attacker to read sensitive configuration settings such as usernames, passwords, and other sensitive RTU data due to insecure permission assignment. |
References
| Link | Providers |
|---|---|
| https://www.mogozobo.com/ |
|
| https://www.mogozobo.com/?p=3593 |
|
History
Tue, 10 Sep 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered on Mitsubishi Electric ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A world-readable /usr/smartrtu/init/settings.xml configuration file on the file system allows an attacker to read sensitive configuration settings such as usernames, passwords, and other sensitive RTU data due to insecure permission assignment. | An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A world-readable /usr/smartrtu/init/settings.xml configuration file on the file system allows an attacker to read sensitive configuration settings such as usernames, passwords, and other sensitive RTU data due to insecure permission assignment. |
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-09-10T17:06:17.053Z
Reserved: 2019-08-10T00:00:00.000Z
Link: CVE-2019-14925
No data.
Status : Modified
Published: 2019-10-28T13:15:10.600
Modified: 2024-11-21T04:27:41.697
Link: CVE-2019-14925
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD