Resource exhaustion in Mitsubishi Electric products - CVE-2019-6535
Published: January 30, 2019
Vulnerability identifier: #VU17277
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2019-6535
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vendor: Mitsubishi Electric
Affected software:
Q100UDEHCPU
Q50UDEHCPU
Q26UDEHCPU
Q20UDEHCPU
Q13UDEHCPU
Q10UDEHCPU
Q06UDEHCPU
Q04UDEHCPU
Q26UDPVCPU
Q13UDPVCPU
Q06UDPVCPU
Q04UDPVCPU
Q26UDVCPU
Q13UDVCPU
Q06UDVCPU
Q04UDVCPU
Q03UDVCPU
Q100UDEHCPU
Q50UDEHCPU
Q26UDEHCPU
Q20UDEHCPU
Q13UDEHCPU
Q10UDEHCPU
Q06UDEHCPU
Q04UDEHCPU
Q26UDPVCPU
Q13UDPVCPU
Q06UDPVCPU
Q04UDPVCPU
Q26UDVCPU
Q13UDVCPU
Q06UDVCPU
Q04UDVCPU
Q03UDVCPU
Detailed vulnerability description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to resource exhaustion when handling malicious input. A remote attacker can send specific bytes over Port 5007, consume excessive resources and cause Ethernet stack crash.
How to mitigate CVE-2019-6535
Update the affected to the latest versions.