Resource exhaustion in Mitsubishi Electric FR Configurator2 - CVE-2019-10972

 

Resource exhaustion in Mitsubishi Electric FR Configurator2 - CVE-2019-10972

Published: July 29, 2019 / Updated: July 29, 2019


Vulnerability identifier: #VU19524
CSH Severity: Low
CVSS v4: 6.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-10972
CWE-ID: CWE-400
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a local attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to the CPU exhaustion when an attacker provides the target with a rogue project file (.frc2). A remote attacker can trick a victim to open the rogue project, trigger CPU exhaustion and cause the software to quit responding until the application is restarted.


Affected software

Mitsubishi Electric FR Configurator2

How to mitigate CVE-2019-10972

Install updates from vendor's website.

Mitsubishi Electric FR Configurator2 - update to 1.17T

External References

Related Security Bulletins