Mitsubishi Electric FR Configurator2 is prone to the following security vulnerabilities:
1. An XML External Entity injection vulnerability
2.A denial-of-service vulnerability
Attackers can exploit these issues to gain access to sensitive information or consumption of resources and cause denial-of-service condition.
Mitsubishi Electric FR Configurator2 versions 1.16S and prior are vulnerable.
Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: vuldb@securityfocus.com.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Bugtraq ID: | 109350 |
Class: | Unknown |
CVE: | CVE-2019-10976 CVE-2019-10972 |
Remote: | Yes |
Local: | No |
Published: | Jul 23 2019 12:00AM |
Updated: | Jul 23 2019 12:00AM |
Credit: | Applied Risk |
Vulnerable: | Mitsubishi Electric FR Configurator2 1.16S Mitsubishi Electric FR Configurator2 0 |
Not Vulnerable: | Mitsubishi Electric FR Configurator2 1.17T |
References:
- Mitsubishi Electric Homepage (Mitsubishi)
- ICSA-19-204-01 : Mitsubishi Electric FR Configurator2 (ICS CERT)
- XML Vulnerability in FR Configurator2 (Mitsubishi Electric)
from SecurityFocus Vulnerabilities https://ift.tt/2Y3UC5O
No comments:
Post a Comment
Note: Only a member of this blog may post a comment.