Vuln: Mitsubishi Electric FR Configurator2 ICSA-19-204-01 Multiple Security Vulnerabilities



Mitsubishi Electric FR Configurator2 is prone to the following security vulnerabilities:

1. An XML External Entity injection vulnerability
2.A denial-of-service vulnerability

Attackers can exploit these issues to gain access to sensitive information or consumption of resources and cause denial-of-service condition.

Mitsubishi Electric FR Configurator2 versions 1.16S and prior are vulnerable.
exploit



Currently, we are not aware of any working exploits. If you feel we are in error or if you are aware of more recent information, please mail us at: vuldb@securityfocus.com.
solution



Solution:
Updates are available. Please see the references or vendor advisory for more information.

info



Bugtraq ID:109350
Class:Unknown
CVE:CVE-2019-10976
CVE-2019-10972
Remote:Yes
Local:No
Published:Jul 23 2019 12:00AM
Updated:Jul 23 2019 12:00AM
Credit:Applied Risk
Vulnerable:Mitsubishi Electric FR Configurator2 1.16S
Mitsubishi Electric FR Configurator2 0
Not Vulnerable:Mitsubishi Electric FR Configurator2 1.17T
references



from SecurityFocus Vulnerabilities https://ift.tt/2Y3UC5O