MEDIUM · 5.4

CVE-2019-14928

An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A number of stored cross-site script (XSS) vulnerabilities allow an attacker...

Vulnerability Description

An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A number of stored cross-site script (XSS) vulnerabilities allow an attacker to inject malicious code directly into the application. An example input variable vulnerable to stored XSS is SerialInitialModemString in the index.php page.

CVSS Score

5.4

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
MitsubishielectricSmartrtu Firmware<= 2.02
MitsubishielectricSmartrtu-
IneaMe-Rtu Firmware<= 3.0
IneaMe-Rtu-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-14928?

CVE-2019-14928 is a vulnerability with a CVSS score of 5.4 (MEDIUM). An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A number of stored cross-site script (XSS) vulnerabilities allow an attacker...

How severe is CVE-2019-14928?

CVE-2019-14928 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-14928?

Check the references section above for vendor advisories and patch information. Affected products include: Mitsubishielectric Smartrtu Firmware, Mitsubishielectric Smartrtu, Inea Me-Rtu Firmware, Inea Me-Rtu.