Rewterz

Rewterz Threat Advisory – Prima Systems FlexAir Multiple Vulnerabilities

August 1, 2019
Rewterz

Rewterz Threat Advisory – CVE 2019-10974 – NREL EnergyPlus Denial of Service Vulnerability

August 1, 2019

Rewterz Threat Advisory – Mitsubishi Electric FR Configurator2 Multiple Vulnerabilities

Severity

Medium

Analysis Summary

CVE 2019-10976

This vulnerability is triggered when input passed to the XML parser is not sanitized while parsing the XML project and/or template file (.frc2). Once a user opens the file, the attacker could read arbitrary files.

CVE 2019-10972

This vulnerability can be triggered when an attacker provides the target with a rogue project file (.frc2). Once a user opens the rogue project, CPU exhaustion occurs, which causes the software to quit responding until the application is restarted.

Impact

Uncontrolled Resource Consumption

Affected Vendors

Mitsubishi Electric

Affected Products

Mitsubishi Electric FR Configurator2 Version 1.16S and prior

Remediation

Mitsubishi Electric has released Version 1.17T for the reported vulnerabilities.

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.