Resource exhaustion in Mitsubishi Electric products - CVE-2019-13555

 

Resource exhaustion in Mitsubishi Electric products - CVE-2019-13555

Published: November 11, 2019


Vulnerability identifier: #VU22634
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-13555
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to improper resource management. A remote attacker can trigger resource exhaustion and cause the FTP service to enter a denial-of-service condition dependent on the timing at which a remote attacker connects to the FTP server on the affected CPU modules.


Affected software

Q26UDPVCPU
Q50UDEHCPU
Q26UDEHCPU
Q100UDEHCPU
Q20UDEHCPU
Q13UDEHCPU
Q10UDEHCPU
Q06UDEHCPU
Q04UDEHCPU
Q03UDVCPU
Q04UDVCPU
Q06UDVCPU
Q13UDVCPU
Q26UDVCPU
Q04UDPVCPU
Q06UDPVCPU
Q13UDPVCPU
MELSEC-L L02CPU
MELSEC-L L06CPU
MELSEC-L L26CPU
MELSEC-L L26CPU-BT
MELSEC-Q Q03UDECPU
MELSEC-L L02CPU-P
MELSEC-L L06CPU-CM
MELSEC-L L26CPU-BT-CM
MELSEC-L L26CPU-CM
MELSEC-L L06CPU-P
MELSEC-L L02CPU-CM
MELSEC-L L26CPU-PBT
MELSEC-L L26CPU-P

How to mitigate CVE-2019-13555

Install updates from vendor's website.


External References

Related Security Bulletins