Vulnerability Description
Mitsubishi Electric Q03/04/06/13/26UDVCPU: serial number 20081 and prior, Q04/06/13/26UDPVCPU: serial number 20081 and prior, and Q03UDECPU, Q04/06/10/13/20/26/50/100UDEHCPU: serial number 20101 and prior. A remote attacker can send specific bytes over Port 5007 that will result in an Ethernet stack crash and disruption to USB communication.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mitsubishielectric | Q03Udvcpu Firmware | <= 20081 |
| Mitsubishielectric | Q03Udvcpu | - |
| Mitsubishielectric | Q04Udvcpu Firmware | <= 20081 |
| Mitsubishielectric | Q04Udvcpu | - |
| Mitsubishielectric | Q06Udvcpu Firmware | <= 20081 |
| Mitsubishielectric | Q06Udvcpu | - |
| Mitsubishielectric | Q13Udvcpu Firmware | <= 20081 |
| Mitsubishielectric | Q13Udvcpu | - |
| Mitsubishielectric | Q26Udvcpu Firmware | <= 20081 |
| Mitsubishielectric | Q26Udvcpu | - |
| Mitsubishielectric | Q04Udpvcpu Firmware | <= 20081 |
| Mitsubishielectric | Q04Udpvcpu | - |
| Mitsubishielectric | Q06Udpvcpu Firmware | <= 20081 |
| Mitsubishielectric | Q06Udpvcpu | - |
| Mitsubishielectric | Q13Udpvcpu Firmware | <= 20081 |
| Mitsubishielectric | Q13Udpvcpu | - |
| Mitsubishielectric | Q26Udpvcpu Firmware | <= 20081 |
| Mitsubishielectric | Q26Udpvcpu | - |
| Mitsubishielectric | Q03Udecpu Firmware | <= 20101 |
| Mitsubishielectric | Q03Udecpu | - |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/106771Third Party AdvisoryVDB Entry
- https://www.cisa.gov/news-events/ics-advisories/icsa-19-029-02
- http://www.securityfocus.com/bid/106771Third Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-19-029-02Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2019-6535?
CVE-2019-6535 is a vulnerability with a CVSS score of 7.5 (HIGH). Mitsubishi Electric Q03/04/06/13/26UDVCPU: serial number 20081 and prior, Q04/06/13/26UDPVCPU: serial number 20081 and prior, and Q03UDECPU, Q04/06/10/13/20/26/50/100UDEHCPU: serial number 20101 and p...
How severe is CVE-2019-6535?
CVE-2019-6535 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-6535?
Check the references section above for vendor advisories and patch information. Affected products include: Mitsubishielectric Q03Udvcpu Firmware, Mitsubishielectric Q03Udvcpu, Mitsubishielectric Q04Udvcpu Firmware, Mitsubishielectric Q04Udvcpu, Mitsubishielectric Q06Udvcpu Firmware.