CVE-2019-14930
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Undocumented hard-coded user passwords for root, ineaadmin, mitsadmin, an...
Affects 4 products across 2 vendors.
Software contains embedded passwords or keys that cannot be changed by the administrator.
Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.
CVE-2019-14930 affects Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. The vulnerability involves undocumented hard-coded user passwords for root, ineaadmin, mitsadmin, and maint, allowing unauthorized access. Additionally, the accounts ineaadmin and mitsadmin can escalate privileges to root without a password due to insecure entries in /etc/sudoers. This high-severity issue poses significant risks to operational technology environments, particularly in terms of safety and control system integrity.
BSID: BS-2019-GLOBAL-135461-C • Model: Qwen/Qwen2.5-72B-Instruct-AWQ • Confidence: HIGH
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2019-14930?
What is the CVSS score for CVE-2019-14930?
Is CVE-2019-14930 actively exploited?
How do I remediate CVE-2019-14930?
What systems are affected by CVE-2019-14930?
What NERC-CIP standard applies to CVE-2019-14930?
What IEC 62443 requirement maps to CVE-2019-14930?
| CVE ID | CVE-2019-14930 |
|---|---|
| BSID | BS-2019-GLOBAL-135461-C BreachSpider Global ID |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| Published | 2019-10-28 |
| Last Modified | 2024-11-21 |
| ICS Relevance | 100% |
| Weakness (CWE) | |
| Verticals | |
| Source | NVD |
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Undocumented hard-coded user passwords for root, ineaadmin, mitsadmin, and maint could allow an attacker to gain unauthorised access to the RTU. (Also, the accounts ineaadmin and mitsadmin are able to escalate privileges to root without supplying a password due to insecure entries in /etc/sudoers on the RTU.)
Source: NIST NVD / MITRE CVE Database
The attack vector is network-based, requiring no user interaction. An attacker can exploit the hard-coded credentials to gain unauthorized access to the RTU device, potentially leading to full control over the device. The lack of proper authentication and authorization mechanisms exacerbates the risk, as the ineaadmin and mitsadmin accounts can escalate privileges to root without additional authentication.
Exploitation Likelihood: MEDIUM
| Vendor | Product | Fixed Version |
|---|---|---|
| Inea | Me-Rtu Firmware | — |
| Inea | Me-Rtu | — |
| Mitsubishi Electric | Smartrtu Firmware | — |
| Mitsubishi Electric | Smartrtu | — |
No patch URL on record. Monitor vendor security advisories directly.
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
Implement strong access controls and regularly update device firmware to the latest version. Use network segmentation to isolate critical systems and monitor for unusual login attempts.
No reliable network detection signature exists for this vulnerability class — apply the compensating controls above and the vendor patch. SAGE only publishes a network rule when a concrete on-the-wire signature can be grounded in the advisory.
This CVE violates CIP-007-R2 by allowing unauthorized access to critical cyber assets, which can compromise the security and reliability of the power grid.
This CVE maps to SR 7.6 because it involves the use of hard-coded credentials, which can be exploited to gain unauthorized access to the device, violating the principle of secure authentication and authorization.
Virtual patch generated by CITED Relevance SAGE. Validate in isolated environment before production deployment. Compensating control only - does not replace vendor patch.
SAGE Enrichment Record — provenance & audit hash
| Model | Qwen/Qwen2.5-72B-Instruct-AWQ |
|---|---|
| Confidence | HIGH |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 29d6cd7bcb89f293773c3e469ba90bc1dafda3bd70f3cb3f4c343aacde5e7e007ce5c905a998b057f85f12477a198a466d5f443c9d8039afdfcb87683c854e81 |
Critical Severity - Know Your Exposure
A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Check Your Assets Free →