Resource exhaustion in Mitsubishi Electric products - CVE-2019-6535

 

Resource exhaustion in Mitsubishi Electric products - CVE-2019-6535

Published: January 30, 2019


Vulnerability identifier: #VU17277
CSH Severity: Low
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-6535
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to resource exhaustion when handling malicious input. A remote attacker can send specific bytes over Port 5007, consume excessive resources and cause Ethernet stack crash.


Affected software

Q26UDPVCPU
Q03UDVCPU
Q04UDVCPU
Q06UDVCPU
Q13UDVCPU
Q26UDVCPU
Q04UDPVCPU
Q06UDPVCPU
Q13UDPVCPU
Q100UDEHCPU
Q04UDEHCPU
Q06UDEHCPU
Q10UDEHCPU
Q13UDEHCPU
Q20UDEHCPU
Q26UDEHCPU
Q50UDEHCPU

How to mitigate CVE-2019-6535

Update the affected to the latest versions.


External References

Related Security Bulletins