7.5

CVE-2019-6535

Mitsubishi Electric Q03/04/06/13/26UDVCPU: serial number 20081 and prior, Q04/06/13/26UDPVCPU: serial number 20081 and prior, and Q03UDECPU, Q04/06/10/13/20/26/50/100UDEHCPU: serial number 20101 and prior. A remote attacker can send specific bytes over Port 5007 that will result in an Ethernet stack crash and disruption to USB communication.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MitsubishielectricQ03udvcpu Firmware Version <= 20081
   MitsubishielectricQ03udvcpu Version-
MitsubishielectricQ04udvcpu Firmware Version <= 20081
   MitsubishielectricQ04udvcpu Version-
MitsubishielectricQ06udvcpu Firmware Version <= 20081
   MitsubishielectricQ06udvcpu Version-
MitsubishielectricQ13udvcpu Firmware Version <= 20081
   MitsubishielectricQ13udvcpu Version-
MitsubishielectricQ26udvcpu Firmware Version <= 20081
   MitsubishielectricQ26udvcpu Version-
MitsubishielectricQ04udpvcpu Firmware Version <= 20081
   MitsubishielectricQ04udpvcpu Version-
MitsubishielectricQ06udpvcpu Firmware Version <= 20081
   MitsubishielectricQ06udpvcpu Version-
MitsubishielectricQ13udpvcpu Firmware Version <= 20081
   MitsubishielectricQ13udpvcpu Version-
MitsubishielectricQ26udpvcpu Firmware Version <= 20081
   MitsubishielectricQ26udpvcpu Version-
MitsubishielectricQ03udecpu Firmware Version <= 20101
   MitsubishielectricQ03udecpu Version-
MitsubishielectricQ04udehcpu Firmware Version <= 20101
   MitsubishielectricQ04udehcpu Version-
MitsubishielectricQ06udehcpu Firmware Version <= 20101
   MitsubishielectricQ06udehcpu Version-
MitsubishielectricQ10udehcpu Firmware Version <= 20101
   MitsubishielectricQ10udehcpu Version-
MitsubishielectricQ13udehcpu Firmware Version <= 20101
   MitsubishielectricQ13udehcpu Version-
MitsubishielectricQ20udehcpu Firmware Version <= 20101
   MitsubishielectricQ20udehcpu Version-
MitsubishielectricQ26udehcpu Firmware Version <= 20101
   MitsubishielectricQ26udehcpu Version-
MitsubishielectricQ50udehcpu Firmware Version <= 20101
   MitsubishielectricQ50udehcpu Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.49% 0.808
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:N/I:N/A:P
ics-cert@hq.dhs.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource, thereby enabling an actor to influence the amount of resources consumed, eventually leading to the exhaustion of available resources.