Vulnerability Description
Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Electric consumer electronics products (PHOTOVOLTAIC COLOR MONITOR ECO-GUIDE, HEMS adapter, Wi-Fi Interface, Air Conditioning, Induction hob, Mitsubishi Electric HEMS Energy Measurement Unit, Refrigerator, Remote control with Wi-Fi Interface, BATHROOM THERMO VENTILATOR, Rice cooker, Mitsubishi Electric HEMS control adapter, Energy Recovery Ventilator, Smart Switch, Ventilating Fan, Range hood fan, Energy Measurement Unit and Air Purifier) allows a remote unauthenticated attacker to disclose information in the products or cause a denial of service (DoS) condition as a result by sniffing credential information (username and password). The wide range of models/versions of Mitsubishi Electric consumer electronics products are affected by this vulnerability. As for the affected product models/versions, see the Mitsubishi Electric's advisory which is listed in [References] section.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mitsubishielectric | Mac-557If-E Firmware | All versions |
| Mitsubishielectric | Mac-557If-E | - |
| Mitsubishielectric | Mac-557If-E1 Firmware | All versions |
| Mitsubishielectric | Mac-557If-E1 | - |
| Mitsubishielectric | Pac-Wf010-E Firmware | All versions |
| Mitsubishielectric | Pac-Wf010-E | - |
| Mitsubishielectric | Mac-566Ifb-E Firmware | All versions |
| Mitsubishielectric | Mac-566Ifb-E | - |
| Mitsubishielectric | Mac-576If-E1 Firmware | All versions |
| Mitsubishielectric | Mac-576If-E1 | - |
| Mitsubishielectric | Mac-567Ifb-E Firmware | All versions |
| Mitsubishielectric | Mac-567Ifb-E | - |
| Mitsubishielectric | Mac-567Ifb2-E Firmware | All versions |
| Mitsubishielectric | Mac-567Ifb2-E | - |
| Mitsubishielectric | Mac-558If-E Firmware | All versions |
| Mitsubishielectric | Mac-558If-E | - |
| Mitsubishielectric | Mac-558If-E1 Firmware | All versions |
| Mitsubishielectric | Mac-558If-E1 | - |
| Mitsubishielectric | Mac-559If-E Firmware | All versions |
| Mitsubishielectric | Mac-559If-E | - |
Related Weaknesses (CWE)
References
- https://jvn.jp/vu/JVNVU96767562/index.htmlThird Party Advisory
- https://www.mitsubishielectric.co.jp/psirt/vulnerability/pdf/2022-010.pdfVendor Advisory
- https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-010_en.pdfVendor Advisory
- https://jvn.jp/vu/JVNVU96767562/index.htmlThird Party Advisory
- https://www.mitsubishielectric.co.jp/psirt/vulnerability/pdf/2022-010.pdfVendor Advisory
- https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-010_en.pdfVendor Advisory
FAQ
What is CVE-2022-33321?
CVE-2022-33321 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Electric consumer electronics products (PHOTOVOLTAIC COLOR MONIT...
How severe is CVE-2022-33321?
CVE-2022-33321 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-33321?
Check the references section above for vendor advisories and patch information. Affected products include: Mitsubishielectric Mac-557If-E Firmware, Mitsubishielectric Mac-557If-E, Mitsubishielectric Mac-557If-E1 Firmware, Mitsubishielectric Mac-557If-E1, Mitsubishielectric Pac-Wf010-E Firmware.