First published: Thu Jul 25 2019(Updated: )
Mitsubishi Electric FR Configurator2, Version 1.16S and prior. This vulnerability can be triggered when an attacker provides the target with a rogue project file (.frc2). Once a user opens the rogue project, CPU exhaustion occurs, which causes the software to quit responding until the application is restarted.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Mitsubishielectric Electric Fr Configurator2 | <=1.16s |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-10972 is classified as a high severity vulnerability due to the potential for CPU exhaustion and application unresponsiveness.
To mitigate CVE-2019-10972, users should update Mitsubishi Electric FR Configurator2 to a version later than 1.16S.
The primary risk of CVE-2019-10972 is a denial of service caused by CPU exhaustion, leading to application downtime.
CVE-2019-10972 affects users of Mitsubishi Electric FR Configurator2 versions 1.16S and earlier.
Yes, an attacker can exploit CVE-2019-10972 remotely by delivering a rogue project file to the target user.