HIGH · 7.5

CVE-2022-24296

Use of a Broken or Risky Cryptographic Algorithm vulnerability in Air Conditioning System G-150AD Ver. 3.21 and prior, Air Conditioning System AG-150A-A Ver. 3.21 and prior, Air Conditioning System AG...

Vulnerability Description

Use of a Broken or Risky Cryptographic Algorithm vulnerability in Air Conditioning System G-150AD Ver. 3.21 and prior, Air Conditioning System AG-150A-A Ver. 3.21 and prior, Air Conditioning System AG-150A-J Ver. 3.21 and prior, Air Conditioning System GB-50AD Ver. 3.21 and prior, Air Conditioning System GB-50ADA-A Ver. 3.21 and prior, Air Conditioning System GB-50ADA-J Ver. 3.21 and prior, Air Conditioning System EB-50GU-A Ver. 7.10 and prior, Air Conditioning System EB-50GU-J Ver. 7.10 and prior, Air Conditioning System AE-200J Ver. 7.97 and prior, Air Conditioning System AE-200A Ver. 7.97 and prior, Air Conditioning System AE-200E Ver. 7.97 and prior, Air Conditioning System AE-50J Ver. 7.97 and prior, Air Conditioning System AE-50A Ver. 7.97 and prior, Air Conditioning System AE-50E Ver. 7.97 and prior, Air Conditioning System EW-50J Ver. 7.97 and prior, Air Conditioning System EW-50A Ver. 7.97 and prior, Air Conditioning System EW-50E Ver. 7.97 and prior, Air Conditioning System TE-200A Ver. 7.97 and prior, Air Conditioning System TE-50A Ver. 7.97 and prior and Air Conditioning System TW-50A Ver. 7.97 and prior allows a remote unauthenticated attacker to cause a disclosure of encrypted message of the air conditioning systems by sniffing encrypted communications.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
MitsubishiAe-200A Firmware<= 7.97
MitsubishiAe-200A-
MitsubishiAe-200E Firmware<= 7.97
MitsubishiAe-200E-
MitsubishiAe-200J Firmware<= 7.97
MitsubishiAe-200J-
MitsubishiAe-50A Firmware<= 7.97
MitsubishiAe-50A-
MitsubishiAe-50E Firmware<= 7.97
MitsubishiAe-50E-
MitsubishiAe-50J Firmware<= 7.97
MitsubishiAe-50J-
MitsubishiAg-150A-A Firmware<= 3.21
MitsubishiAg-150A-A-
MitsubishiAg-150A-J Firmware<= 3.21
MitsubishiAg-150A-J-
MitsubishiEb-50Gu-A Firmware<= 7.10
MitsubishiEb-50Gu-A-
MitsubishiEb-50Gu-J Firmware<= 7.10
MitsubishiEb-50Gu-J-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-24296?

CVE-2022-24296 is a vulnerability with a CVSS score of 7.5 (HIGH). Use of a Broken or Risky Cryptographic Algorithm vulnerability in Air Conditioning System G-150AD Ver. 3.21 and prior, Air Conditioning System AG-150A-A Ver. 3.21 and prior, Air Conditioning System AG...

How severe is CVE-2022-24296?

CVE-2022-24296 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-24296?

Check the references section above for vendor advisories and patch information. Affected products include: Mitsubishi Ae-200A Firmware, Mitsubishi Ae-200A, Mitsubishi Ae-200E Firmware, Mitsubishi Ae-200E, Mitsubishi Ae-200J Firmware.