CVE-2019-10976 is a medium-severity vulnerability affecting Mitsubishi Electric FR Configurator2, versions 1.16S and prior. It stems from unsanitized input in the XML parser when opening specially crafted .frc2 project or template files. This allows an attacker to read arbitrary files on a user's system if they are tricked into opening a malicious file. There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.16sCPE matchmatch criteria | cpe:2.3:o:mitsubishielectric:electric_fr_configurator2_firmware:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.