CVE-2019-10976

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
26/07/2019
Last modified:
09/10/2019

Description

Mitsubishi Electric FR Configurator2, Version 1.16S and prior. This vulnerability is triggered when input passed to the XML parser is not sanitized while parsing the XML project and/or template file (.frc2). Once a user opens the file, the attacker could read arbitrary files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:mitsubishielectric:electric_fr_configurator2_firmware:*:*:*:*:*:*:*:* 1.16s (excluding)
cpe:2.3:h:mitsubishielectric:electric_fr_configurator2:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools