CVE-2019-10976: XEE
Mitsubishi Electric FR Configurator2, Version 1.16S and prior. This vulnerability is triggered when input passed to the XML parser is not sanitized while parsing the XML project and/or template file (.frc2). Once a user opens the file, the attacker could read arbitrary files.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-10976?
CVE-2019-10976 is classified as a high severity vulnerability due to the potential exposure of sensitive files.
How do I fix CVE-2019-10976?
To fix CVE-2019-10976, upgrade to a version of Mitsubishi Electric FR Configurator2 later than 1.16S.
What type of attack does CVE-2019-10976 facilitate?
CVE-2019-10976 facilitates an arbitrary file read attack through unhandled XML parsing.
Which versions of Mitsubishi Electric FR Configurator2 are affected by CVE-2019-10976?
Versions up to and including 1.16S of Mitsubishi Electric FR Configurator2 are affected by CVE-2019-10976.
What should users of Mitsubishi Electric FR Configurator2 do regarding CVE-2019-10976?
Users should immediately update their installations of Mitsubishi Electric FR Configurator2 to mitigate CVE-2019-10976.