CVE-2023-29155

CRITICAL

Versions of INEA ME RTU firmware 3.36b and prior do not require authentication to the "root" account on the host system of the device. This could allow an attacker to obtain admin-level access to t...

Affects 2 products across 1 vendor.

BCS6.48
CVSS 3.19.8
EPSS0.9%
Percentile55th
PatchPatched
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-287: Improper Authentication

Software does not prove or insufficiently proves that the user is who they claim to be.

Related Attack Patterns (CAPEC)
CAPEC-57 Utilizing REST's Trust in the System Resource to Obtain Sensitive Data
via CWE-287
CAPEC-633 Token Impersonation
via CWE-287
CAPEC-650 Upload a Web Shell to a Web Server
via CWE-287
CAPEC-194 Fake the Source of Data
via CWE-287
CAPEC-593 Session Hijacking
via CWE-287
Show all 10

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

Versions of INEA ME RTU firmware 3.36b and prior are vulnerable to unauthorized access as the 'root' user without authentication, allowing attackers to gain admin-level access to the host system.

BSID: BS-2023-GLOBAL-350289-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2023-29155?
Versions of INEA ME RTU firmware 3.36b and prior are vulnerable to unauthorized access as the 'root' user without authentication, allowing attackers to gain admin-level access to the host system.
What is the CVSS score for CVE-2023-29155?
CVE-2023-29155 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 0.9%.
Is CVE-2023-29155 actively exploited?
No confirmed active exploitation of CVE-2023-29155 as of 2026-05-30.
How do I remediate CVE-2023-29155?
Priority: IMMEDIATE. Advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-23-304-02
What systems are affected by CVE-2023-29155?
CVE-2023-29155 affects: Inea, Inea.
Vulnerability Details
CVE IDCVE-2023-29155
BSIDBS-2023-GLOBAL-350289-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2023-11-20
Last Modified2024-11-21
ICS Relevance25%
Weakness (CWE)
SourceNVD
Official Description

Versions of INEA ME RTU firmware 3.36b and prior do not require authentication to the "root" account on the host system of the device. This could allow an attacker to obtain admin-level access to the host system.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker can exploit this vulnerability by connecting to the device and accessing the 'root' account without providing any credentials. This can be done over the network if the device is exposed.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Inea Me Rtu Firmware
Inea Me Rtu
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Threat Intelligence
● Threat Intelligence Validated: July 2026 | Threat Age: 978 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashb4a4345584adf41ddaa2f28c3d904cb653f9885b7f2e7c77ccd08a9441270d45ef1ba369944eb0e606e2b250380332c955e2d1330d3e7c0379c9c9b1a2486b5b
Related CVEs affecting Inea
CVE-2023-35762 9.8 Versions of INEA ME RTU firmware 3.36b and prior are vulnerable to operating... CVE-2019-14926 9.8 An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices thr... CVE-2019-14930 9.8 An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices thr... CVE-2019-14931 9.8 An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices thr... CVE-2023-2131 9.8 Versions of INEA ME RTU firmware prior to 3.36 are vulnerable to OS command i...
View all Inea CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →