Transmission of Sensitive Information in Mitsubishi Electric Consumer Electronics
CVE-2022-33321
Key Information:
Summary
A vulnerability exists in several Mitsubishi Electric consumer electronics products due to their reliance on basic authentication for HTTP connections. This flaw allows a remote, unauthenticated attacker to intercept sensitive information, including usernames and passwords, through cleartext transmissions. As a result, attackers can potentially disclose confidential data or induce a denial of service (DoS) condition. The issue affects a variety of products, highlighting the need for improved security measures to safeguard user data against unauthorized access and exploitation.
Affected Version(s)
Air Conditioning MFZ-GXT50/60/73VFK versions 35.00 and prior
Air Conditioning MFZ-XT50/60VFK versions 35.00 and prior
Air Conditioning MSXY-FP05/07/10/13/18/20/24VGK-SG1 versions 35.00 and prior
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved