HIGH · 7.5

CVE-2019-6535

Mitsubishi Electric Q03/04/06/13/26UDVCPU: serial number 20081 and prior, Q04/06/13/26UDPVCPU: serial number 20081 and prior, and Q03UDECPU, Q04/06/10/13/20/26/50/100UDEHCPU: serial number 20101 and p...

Vulnerability Description

Mitsubishi Electric Q03/04/06/13/26UDVCPU: serial number 20081 and prior, Q04/06/13/26UDPVCPU: serial number 20081 and prior, and Q03UDECPU, Q04/06/10/13/20/26/50/100UDEHCPU: serial number 20101 and prior. A remote attacker can send specific bytes over Port 5007 that will result in an Ethernet stack crash and disruption to USB communication.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
MitsubishielectricQ03Udvcpu Firmware<= 20081
MitsubishielectricQ03Udvcpu-
MitsubishielectricQ04Udvcpu Firmware<= 20081
MitsubishielectricQ04Udvcpu-
MitsubishielectricQ06Udvcpu Firmware<= 20081
MitsubishielectricQ06Udvcpu-
MitsubishielectricQ13Udvcpu Firmware<= 20081
MitsubishielectricQ13Udvcpu-
MitsubishielectricQ26Udvcpu Firmware<= 20081
MitsubishielectricQ26Udvcpu-
MitsubishielectricQ04Udpvcpu Firmware<= 20081
MitsubishielectricQ04Udpvcpu-
MitsubishielectricQ06Udpvcpu Firmware<= 20081
MitsubishielectricQ06Udpvcpu-
MitsubishielectricQ13Udpvcpu Firmware<= 20081
MitsubishielectricQ13Udpvcpu-
MitsubishielectricQ26Udpvcpu Firmware<= 20081
MitsubishielectricQ26Udpvcpu-
MitsubishielectricQ03Udecpu Firmware<= 20101
MitsubishielectricQ03Udecpu-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2019-6535?

CVE-2019-6535 is a vulnerability with a CVSS score of 7.5 (HIGH). Mitsubishi Electric Q03/04/06/13/26UDVCPU: serial number 20081 and prior, Q04/06/13/26UDPVCPU: serial number 20081 and prior, and Q03UDECPU, Q04/06/10/13/20/26/50/100UDEHCPU: serial number 20101 and p...

How severe is CVE-2019-6535?

CVE-2019-6535 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2019-6535?

Check the references section above for vendor advisories and patch information. Affected products include: Mitsubishielectric Q03Udvcpu Firmware, Mitsubishielectric Q03Udvcpu, Mitsubishielectric Q04Udvcpu Firmware, Mitsubishielectric Q04Udvcpu, Mitsubishielectric Q06Udvcpu Firmware.