CVE-2022-33321
Severity CVSS v4.0:
Pending analysis
Type:
CWE-319
Cleartext Transmission of Sensitive Information
Publication date:
08/11/2022
Last modified:
01/05/2025
Description
Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Electric consumer electronics products (PHOTOVOLTAIC COLOR MONITOR ECO-GUIDE, HEMS adapter, Wi-Fi Interface, Air Conditioning, Induction hob, Mitsubishi Electric HEMS Energy Measurement Unit, Refrigerator, Remote control with Wi-Fi Interface, BATHROOM THERMO VENTILATOR, Rice cooker, Mitsubishi Electric HEMS control adapter, Energy Recovery Ventilator, Smart Switch, Ventilating Fan, Range hood fan, Energy Measurement Unit and Air Purifier) allows a remote unauthenticated attacker to disclose information in the products or cause a denial of service (DoS) condition as a result by sniffing credential information (username and password).<br />
The wide range of models/versions of Mitsubishi Electric consumer electronics products are affected by this vulnerability.<br />
As for the affected product models/versions, see the Mitsubishi Electric&#39;s advisory which is listed in [References] section.<br />
<br />
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:mitsubishielectric:mac-557if-e_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mitsubishielectric:mac-557if-e:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mitsubishielectric:mac-557if-e1_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mitsubishielectric:mac-557if-e1:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mitsubishielectric:pac-wf010-e_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mitsubishielectric:pac-wf010-e:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mitsubishielectric:mac-566ifb-e_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mitsubishielectric:mac-566ifb-e:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mitsubishielectric:mac-576if-e1_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mitsubishielectric:mac-576if-e1:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mitsubishielectric:mac-567ifb-e_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mitsubishielectric:mac-567ifb-e:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mitsubishielectric:mac-567ifb2-e_firmware:*:*:*:*:*:*:*:* | ||
| cpe:2.3:h:mitsubishielectric:mac-567ifb2-e:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:mitsubishielectric:mac-558if-e_firmware:*:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- https://jvn.jp/vu/JVNVU96767562/index.html
- https://www.mitsubishielectric.co.jp/psirt/vulnerability/pdf/2022-010.pdf
- https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-010_en.pdf
- https://jvn.jp/vu/JVNVU96767562/index.html
- https://www.mitsubishielectric.co.jp/psirt/vulnerability/pdf/2022-010.pdf
- https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-010_en.pdf



