Vulnerability Description
Mitsubishi Electric FR Configurator2, Version 1.16S and prior. This vulnerability can be triggered when an attacker provides the target with a rogue project file (.frc2). Once a user opens the rogue project, CPU exhaustion occurs, which causes the software to quit responding until the application is restarted.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mitsubishielectric | Electric Fr Configurator2 | <= 1.16s |
Related Weaknesses (CWE)
References
- https://www.us-cert.gov/ics/advisories/icsa-19-204-01Third Party AdvisoryUS Government Resource
- https://www.us-cert.gov/ics/advisories/icsa-19-204-01Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2019-10972?
CVE-2019-10972 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Mitsubishi Electric FR Configurator2, Version 1.16S and prior. This vulnerability can be triggered when an attacker provides the target with a rogue project file (.frc2). Once a user opens the rogue p...
How severe is CVE-2019-10972?
CVE-2019-10972 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-10972?
Check the references section above for vendor advisories and patch information. Affected products include: Mitsubishielectric Electric Fr Configurator2.