ICSA-25-105-09
·
Published 2025-05-06
·
View on CISA ICS-CERT ↗
Mitsubishi Electric Europe B.V. smartRTU
CVSS 9.8
CRITICAL
Risk Summary
Successful exploitation of these vulnerabilities could allow a remote unauthenticated attacker to disclose, tamper with, destroy or delete information in the product, or cause a denial-of service condition on the product.
CVEs (2)
Remediations
- Mitsubishi Electric Europe B.V. recommends that users take note of the following mitigation measures to minimize the risk of exploiting this vulnerability:
- Use a firewall or virtual private network (VPN), etc. to prevent unauthorized access when Internet access is required.
- Use within a LAN and block access from untrusted networks and hosts through firewalls.
- Use web application firewall (WAF) to prevent to filter, monitor and block any malicious HTTP/HTTPS traffic.
- Allow web client access from trusted networks only.
- For more information, please see Mitsubishi Electric Europe MEU_PSIRT_2025-3128 under the "Vulnerability Information" section.
Affected Vendors
Mitsubishi Electric Europe B.V.
Affected Products (1)
Mitsubishi Electric Europe B.V.
·
smartRTU
<=3.37
Affected Sectors
Critical Manufacturing
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more