Mitsubishi Electric released a new version to handle improper restriction of XML external entity reference and uncontrolled resource consumption vulnerabilities in its FR Configurator2, according to a report with NCCIC.

Successful exploitation of these vulnerabilities, discovered by Applied Risk, may enable arbitrary files to be read or cause a denial-of-service condition.

RELATED STORIES
Johnson Controls has Fix for exacqVision Server
Schneider Fixes Floating License Manager
Schneider has Fix for IGSS Vulnerability
AVEVA Handles Floating License Manager Issue

Used for configuring Mitsubishi variable frequency drives, FR Configurator2 Version 1.16S and prior suffer from the issues.

One vulnerability is triggered when input passed to the XML parser is not sanitized while parsing the XML project and/or template file (.frc2). Once a user opens the file, the attacker could read arbitrary files.

Schneider Bold

CVE-2019-10976 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 7.1.

In addition, another vulnerability can end up triggered when an attacker provides the target with a rogue project file (.frc2). Once a user opens the rogue project, CPU exhaustion occurs, which causes the software to quit responding until the application is restarted.

CVE-2019-10972 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 5.5.

The product sees use mainly in the critical manufacturing sector on a global basis.

No known public exploits specifically target these vulnerabilities. These vulnerabilities are not exploitable remotely. However, an attacker with low skill level could leverage the vulnerabilities.

Mitsubishi Electric released Version 1.17T for the reported vulnerabilities. Click here for additional information about the vulnerabilities and how to obtain the update.

Additional information about the vulnerabilities or Mitsubishi Electric’s compensating control is available by contacting a local Mitsubishi Electric representative.

ISSSource

Pin It on Pinterest

Share This