Transmission of Sensitive Information in Mitsubishi Electric Consumer Electronics
CVE-2022-33321

9.8CRITICAL

Summary

A vulnerability exists in several Mitsubishi Electric consumer electronics products due to their reliance on basic authentication for HTTP connections. This flaw allows a remote, unauthenticated attacker to intercept sensitive information, including usernames and passwords, through cleartext transmissions. As a result, attackers can potentially disclose confidential data or induce a denial of service (DoS) condition. The issue affects a variety of products, highlighting the need for improved security measures to safeguard user data against unauthorized access and exploitation.

Affected Version(s)

Air Conditioning MFZ-GXT50/60/73VFK versions 35.00 and prior

Air Conditioning MFZ-XT50/60VFK versions 35.00 and prior

Air Conditioning MSXY-FP05/07/10/13/18/20/24VGK-SG1 versions 35.00 and prior

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.