CRITICAL

CVE-2019-14931

CVSS v3

9.8

CRITICAL

EPSS Score

60.8%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote OS Command Injection vulnerability allows an attacker to execute arbitrary commands on the RTU due to the passing of unsafe user supplied data to the RTU's system shell. Functionality in mobile.php provides users with the ability to ping sites or IP addresses via Mobile Connection Test. When the Mobile Connection Test is submitted, action.php is called to execute the test. An attacker can use a shell command separator (;) in the host variable to execute operating system commands upon submitting the test data.

Technical details

Published
10/28/2019

Frequently asked questions

What is CVE-2019-14931?

An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote OS Command Injection vulnerability allows an attacker to execute arbitrary commands on the RTU due to the passing of unsafe user supplied data to the RTU's system shell. Functionality in mobile.php provides users with the ability to ping sites or IP addresses via Mobile Connection Test. When the Mobile Connection Test is submitted, action.php is called to execute the test. An attacker can use a shell command separator (;) in the host variable to execute operating system commands upon submitting the test data.

Is CVE-2019-14931 actively exploited?

Active exploitation of CVE-2019-14931 has not been confirmed. The EPSS score is 60.8%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2019-14931?

CVE-2019-14931 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2019-14931 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.