CVE-2023-2131

CRITICAL

Versions of INEA ME RTU firmware prior to 3.36 are vulnerable to OS command injection, which could allow an attacker to remotely execute arbitrary code.

Affects 2 products across 1 vendor.

BCS7.37
CVSS 3.19.8
EPSS1.7%
Percentile75th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-78: OS Command Injection

Attacker injects OS commands through application inputs passed to system() or equivalent calls, leading to arbitrary command execution.

Related Attack Patterns (CAPEC)
CAPEC-43 Exploiting Multiple Input Interpretation Layers
via CWE-78
CAPEC-108 Command Line Execution through SQL Injection
via CWE-78
CAPEC-6 Argument Injection
via CWE-78
CAPEC-15 Command Delimiters
via CWE-78
CAPEC-88 OS Command Injection
via CWE-78

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

Versions of INEA ME RTU firmware prior to 3.36 are vulnerable to OS command injection, allowing remote execution of arbitrary code.

BSID: BS-2023-GLOBAL-059762-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2023-2131?
Versions of INEA ME RTU firmware prior to 3.36 are vulnerable to OS command injection, allowing remote execution of arbitrary code.
What is the CVSS score for CVE-2023-2131?
CVE-2023-2131 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 1.7%.
Is CVE-2023-2131 actively exploited?
No confirmed active exploitation of CVE-2023-2131 as of 2026-05-30.
How do I remediate CVE-2023-2131?
Priority: IMMEDIATE. Advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-23-110-01
What systems are affected by CVE-2023-2131?
CVE-2023-2131 affects: Inea, Inea.
Vulnerability Details
CVE IDCVE-2023-2131
BSIDBS-2023-GLOBAL-059762-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2023-04-20
Last Modified2024-11-21
ICS Relevance25%
Weakness (CWE)
SourceNVD
Official Description

Versions of INEA ME RTU firmware prior to 3.36 are vulnerable to OS command injection, which could allow an attacker to remotely execute arbitrary code.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker can exploit this vulnerability by injecting malicious OS commands through a vulnerable input field, leading to arbitrary code execution with the privileges of the application.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Inea Me Rtu Firmware
Inea Me Rtu
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 1192 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash3d3dae41c5a24c8892c66a32528ec505010527a3f7d4c8a15ded9653f765254e720076ae7890e1267b79d787083e6baaa3b15b28c5c24650e3d4e2f7a95f7605
Related CVEs affecting Inea
CVE-2023-35762 9.8 Versions of INEA ME RTU firmware 3.36b and prior are vulnerable to operating... CVE-2019-14926 9.8 An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices thr... CVE-2019-14930 9.8 An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices thr... CVE-2019-14931 9.8 An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices thr... CVE-2023-29155 9.8 Versions of INEA ME RTU firmware 3.36b and prior do not require authenticatio...
View all Inea CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →