PT-2022-21770 · Mitsubishi · Mitsubishi Electric Consumer Electronics Products

Published

2022-11-08

·

Updated

2023-10-26

·

CVE-2022-33322

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Mitsubishi Electric consumer electronics products (affected versions not specified)
Description A cross-site scripting vulnerability in Mitsubishi Electric consumer electronics products allows a remote unauthenticated attacker to execute a malicious script on a user's browser to disclose information. The vulnerability affects a wide range of models and versions of Mitsubishi Electric consumer electronics products, including Air Conditioning, Wi-Fi Interface, Refrigerator, HEMS adapter, Remote control with Wi-Fi Interface, BATHROOM THERMO VENTILATOR, Rice cooker, Mitsubishi Electric HEMS control adapter, Energy Recovery Ventilator, Smart Switch, and Air Purifier.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-33322

Affected Products

Mitsubishi Electric Consumer Electronics Products