CVE-2022-33322
—CVSS 3.1
6.1 medium
EPSS
<1%p58
Published
()
Modified
Description
Cross-site scripting vulnerability in Mitsubishi Electric consumer electronics products (Air Conditioning, Wi-Fi Interface, Refrigerator, HEMS adapter, Remote control with Wi-Fi Interface, BATHROOM THERMO VENTILATOR, Rice cooker, Mitsubishi Electric HEMS control adapter, Energy Recovery Ventilator, Smart Switch and Air Purifier) allows a remote unauthenticated attacker to execute an malicious script on a user's browser to disclose information, etc. The wide range of models/versions of Mitsubishi Electric consumer electronics products are affected by this vulnerability. As for the affected product models/versions, see the Mitsubishi Electric's advisory which is listed in [References] section.
- Vendors
- mitsubishielectric
- Products
- mac-587if-e firmware, mac-587if2-e firmware, mac-507if-e firmware, mac-588if-e firmware, s-mac-002if firmware, ma-ew85s-e firmware, ma-ew85s-uk firmware, mfz-gxt50\/60\/73vfk firmware, mfz-xt50\/60vfk firmware, msxy-fp05\/07\/10\/13\/18\/20\/24vgk-sg1 firmware, msy-gp10\/13\/15\/18\/20\/24vfk-sg1 firmware, msz-ap15\/20\/25\/35\/42\/50\/60\/71vgk-e2 firmware
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
In the news0 stories
No ingested article mentions this CVE yet.