CRITICAL · 9.8

CVE-2022-33321

Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Electric consumer electronics products (PHOTOVOLTAIC COLOR MONIT...

Vulnerability Description

Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Electric consumer electronics products (PHOTOVOLTAIC COLOR MONITOR ECO-GUIDE, HEMS adapter, Wi-Fi Interface, Air Conditioning, Induction hob, Mitsubishi Electric HEMS Energy Measurement Unit, Refrigerator, Remote control with Wi-Fi Interface, BATHROOM THERMO VENTILATOR, Rice cooker, Mitsubishi Electric HEMS control adapter, Energy Recovery Ventilator, Smart Switch, Ventilating Fan, Range hood fan, Energy Measurement Unit and Air Purifier) allows a remote unauthenticated attacker to disclose information in the products or cause a denial of service (DoS) condition as a result by sniffing credential information (username and password). The wide range of models/versions of Mitsubishi Electric consumer electronics products are affected by this vulnerability. As for the affected product models/versions, see the Mitsubishi Electric's advisory which is listed in [References] section.

CVSS Score

9.8

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
MitsubishielectricMac-557If-E FirmwareAll versions
MitsubishielectricMac-557If-E-
MitsubishielectricMac-557If-E1 FirmwareAll versions
MitsubishielectricMac-557If-E1-
MitsubishielectricPac-Wf010-E FirmwareAll versions
MitsubishielectricPac-Wf010-E-
MitsubishielectricMac-566Ifb-E FirmwareAll versions
MitsubishielectricMac-566Ifb-E-
MitsubishielectricMac-576If-E1 FirmwareAll versions
MitsubishielectricMac-576If-E1-
MitsubishielectricMac-567Ifb-E FirmwareAll versions
MitsubishielectricMac-567Ifb-E-
MitsubishielectricMac-567Ifb2-E FirmwareAll versions
MitsubishielectricMac-567Ifb2-E-
MitsubishielectricMac-558If-E FirmwareAll versions
MitsubishielectricMac-558If-E-
MitsubishielectricMac-558If-E1 FirmwareAll versions
MitsubishielectricMac-558If-E1-
MitsubishielectricMac-559If-E FirmwareAll versions
MitsubishielectricMac-559If-E-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-33321?

CVE-2022-33321 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Cleartext Transmission of Sensitive Information vulnerability due to the use of Basic Authentication for HTTP connections in Mitsubishi Electric consumer electronics products (PHOTOVOLTAIC COLOR MONIT...

How severe is CVE-2022-33321?

CVE-2022-33321 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2022-33321?

Check the references section above for vendor advisories and patch information. Affected products include: Mitsubishielectric Mac-557If-E Firmware, Mitsubishielectric Mac-557If-E, Mitsubishielectric Mac-557If-E1 Firmware, Mitsubishielectric Mac-557If-E1, Mitsubishielectric Pac-Wf010-E Firmware.