PT-2022-3399 · Unknown · Air Conditioning System Ae-50A+5

Published

2022-06-08

·

Updated

2022-06-17

·

CVE-2022-24296

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Air Conditioning System G-150AD versions 3.21 and prior Air Conditioning System AG-150A-A versions 3.21 and prior Air Conditioning System AG-150A-J versions 3.21 and prior Air Conditioning System GB-50AD versions 3.21 and prior Air Conditioning System GB-50ADA-A versions 3.21 and prior Air Conditioning System GB-50ADA-J versions 3.21 and prior Air Conditioning System EB-50GU-A versions 7.10 and prior Air Conditioning System EB-50GU-J versions 7.10 and prior Air Conditioning System AE-200J versions 7.97 and prior Air Conditioning System AE-200A versions 7.97 and prior Air Conditioning System AE-200E versions 7.97 and prior Air Conditioning System AE-50J versions 7.97 and prior Air Conditioning System AE-50A versions 7.97 and prior Air Conditioning System AE-50E versions 7.97 and prior Air Conditioning System EW-50J versions 7.97 and prior Air Conditioning System EW-50A versions 7.97 and prior Air Conditioning System EW-50E versions 7.97 and prior Air Conditioning System TE-200A versions 7.97 and prior Air Conditioning System TE-50A versions 7.97 and prior Air Conditioning System TW-50A versions 7.97 and prior
Description The issue is related to the use of a broken or risky cryptographic algorithm, allowing a remote unauthenticated attacker to cause a disclosure of encrypted messages of the air conditioning systems by sniffing encrypted communications. This can lead to the exposure of sensitive information.
Recommendations For Air Conditioning System G-150AD versions 3.21 and prior, update to a version that uses a secure cryptographic algorithm. For Air Conditioning System AG-150A-A versions 3.21 and prior, update to a version that uses a secure cryptographic algorithm. For Air Conditioning System AG-150A-J versions 3.21 and prior, update to a version that uses a secure cryptographic algorithm. For Air Conditioning System GB-50AD versions 3.21 and prior, update to a version that uses a secure cryptographic algorithm. For Air Conditioning System GB-50ADA-A versions 3.21 and prior, update to a version that uses a secure cryptographic algorithm. For Air Conditioning System GB-50ADA-J versions 3.21 and prior, update to a version that uses a secure cryptographic algorithm. For Air Conditioning System EB-50GU-A versions 7.10 and prior, update to a version that uses a secure cryptographic algorithm. For Air Conditioning System EB-50GU-J versions 7.10 and prior, update to a version that uses a secure cryptographic algorithm. For Air Conditioning System AE-200J versions 7.97 and prior, update to a version that uses a secure cryptographic algorithm. For Air Conditioning System AE-200A versions 7.97 and prior, update to a version that uses a secure cryptographic algorithm. For Air Conditioning System AE-200E versions 7.97 and prior, update to a version that uses a secure cryptographic algorithm. For Air Conditioning System AE-50J versions 7.97 and prior, update to a version that uses a secure cryptographic algorithm. For Air Conditioning System AE-50A versions 7.97 and prior, update to a version that uses a secure cryptographic algorithm. For Air Conditioning System AE-50E versions 7.97 and prior, update to a version that uses a secure cryptographic algorithm. For Air Conditioning System EW-50J versions 7.97 and prior, update to a version that uses a secure cryptographic algorithm. For Air Conditioning System EW-50A versions 7.97 and prior, update to a version that uses a secure cryptographic algorithm. For Air Conditioning System EW-50E versions 7.97 and prior, update to a version that uses a secure cryptographic algorithm. For Air Conditioning System TE-200A versions 7.97 and prior, update to a version that uses a secure cryptographic algorithm. For Air Conditioning System TE-50A versions 7.97 and prior, update to a version that uses a secure cryptographic algorithm. For Air Conditioning System TW-50A versions 7.97 and prior, update to a version that uses a secure cryptographic algorithm.

Fix

Use of a Broken Cryptographic Algorithm

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04171
CVE-2022-24296

Affected Products

Air Conditioning System Ae-200A
Air Conditioning System Ae-50A
Air Conditioning System Ag-150A-A
Air Conditioning System Eb-50Gu-A
Air Conditioning System Ew-50A
Air Conditioning System Gb-50Ad