CVE-2022-24296

Use of a Broken or Risky Cryptographic Algorithm vulnerability in Air Conditioning System G-150AD Ver. 3.21 and prior, Air Conditioning System AG-150A-A Ver. 3.21 and prior, Air Conditioning System AG-150A-J Ver. 3.21 and prior, Air Conditioning System GB-50AD Ver. 3.21 and prior, Air Conditioning System GB-50ADA-A Ver. 3.21 and prior, Air Conditioning System GB-50ADA-J Ver. 3.21 and prior, Air Conditioning System EB-50GU-A Ver. 7.10 and prior, Air Conditioning System EB-50GU-J Ver. 7.10 and prior, Air Conditioning System AE-200J Ver. 7.97 and prior, Air Conditioning System AE-200A Ver. 7.97 and prior, Air Conditioning System AE-200E Ver. 7.97 and prior, Air Conditioning System AE-50J Ver. 7.97 and prior, Air Conditioning System AE-50A Ver. 7.97 and prior, Air Conditioning System AE-50E Ver. 7.97 and prior, Air Conditioning System EW-50J Ver. 7.97 and prior, Air Conditioning System EW-50A Ver. 7.97 and prior, Air Conditioning System EW-50E Ver. 7.97 and prior, Air Conditioning System TE-200A Ver. 7.97 and prior, Air Conditioning System TE-50A Ver. 7.97 and prior and Air Conditioning System TW-50A Ver. 7.97 and prior allows a remote unauthenticated attacker to cause a disclosure of encrypted message of the air conditioning systems by sniffing encrypted communications.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:mitsubishi:ae-200a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:ae-200a:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:mitsubishi:ae-200e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:ae-200e:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:mitsubishi:ae-200j_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:ae-200j:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:mitsubishi:ae-50a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:ae-50a:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:mitsubishi:ae-50e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:ae-50e:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:mitsubishi:ae-50j_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:ae-50j:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:mitsubishi:ag-150a-a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:ag-150a-a:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:mitsubishi:ag-150a-j_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:ag-150a-j:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:mitsubishi:eb-50gu-a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:eb-50gu-a:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
cpe:2.3:o:mitsubishi:eb-50gu-j_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:eb-50gu-j:-:*:*:*:*:*:*:*

Configuration 11 (hide)

AND
cpe:2.3:o:mitsubishi:ew-50a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:ew-50a:-:*:*:*:*:*:*:*

Configuration 12 (hide)

AND
cpe:2.3:o:mitsubishi:ew-50e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:ew-50e:-:*:*:*:*:*:*:*

Configuration 13 (hide)

AND
cpe:2.3:o:mitsubishi:ew-50j_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:ew-50j:-:*:*:*:*:*:*:*

Configuration 14 (hide)

AND
cpe:2.3:o:mitsubishi:g-150ad_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:g-150ad:-:*:*:*:*:*:*:*

Configuration 15 (hide)

AND
cpe:2.3:o:mitsubishi:gb-50a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:gb-50a:-:*:*:*:*:*:*:*

Configuration 16 (hide)

AND
cpe:2.3:o:mitsubishi:gb-50ada-a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:gb-50ada-a:-:*:*:*:*:*:*:*

Configuration 17 (hide)

AND
cpe:2.3:o:mitsubishi:gb-50ada-j_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:gb-50ada-j:-:*:*:*:*:*:*:*

Configuration 18 (hide)

AND
cpe:2.3:o:mitsubishi:te-200a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:te-200a:-:*:*:*:*:*:*:*

Configuration 19 (hide)

AND
cpe:2.3:o:mitsubishi:te-50a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:te-50a:-:*:*:*:*:*:*:*

Configuration 20 (hide)

AND
cpe:2.3:o:mitsubishi:tw-50a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:tw-50a:-:*:*:*:*:*:*:*

History

17 Jun 2022, 15:36

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : 5.0
v3 : 7.5
CWE CWE-327
CPE cpe:2.3:o:mitsubishi:ae-50j_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:ae-50j:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishi:ag-150a-a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishi:ew-50j_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:ew-50j:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishi:eb-50gu-j_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishi:gb-50ada-a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishi:g-150ad_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:ae-50a:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishi:ew-50e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:te-50a:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishi:ae-50a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishi:gb-50a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:ew-50a:-:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:tw-50a:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishi:tw-50a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishi:ag-150a-j_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:g-150ad:-:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:eb-50gu-a:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishi:ae-200a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishi:te-50a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:ag-150a-j:-:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:ae-200j:-:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:ae-50e:-:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:ag-150a-a:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishi:ae-200j_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishi:ae-50e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishi:ae-200e_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:eb-50gu-j:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishi:ew-50a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:ew-50e:-:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:gb-50ada-j:-:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:te-200a:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishi:gb-50ada-j_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:ae-200a:-:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:gb-50a:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishi:te-200a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:ae-200e:-:*:*:*:*:*:*:*
cpe:2.3:o:mitsubishi:eb-50gu-a_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:mitsubishi:gb-50ada-a:-:*:*:*:*:*:*:*
References (MISC) https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-005_en.pdf - (MISC) https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-005_en.pdf - Vendor Advisory
References (MISC) https://jvn.jp/vu/JVNVU95298925/index.html - (MISC) https://jvn.jp/vu/JVNVU95298925/index.html - Third Party Advisory
References (MISC) https://www.mee.co.jp/psirt/vulnerability/pdf/2022-001.pdf - (MISC) https://www.mee.co.jp/psirt/vulnerability/pdf/2022-001.pdf - Third Party Advisory
First Time Mitsubishi ew-50e Firmware
Mitsubishi ew-50j
Mitsubishi ew-50a
Mitsubishi gb-50a Firmware
Mitsubishi ae-50e
Mitsubishi eb-50gu-a Firmware
Mitsubishi ag-150a-a Firmware
Mitsubishi gb-50ada-a
Mitsubishi ae-200j
Mitsubishi eb-50gu-j Firmware
Mitsubishi te-50a Firmware
Mitsubishi ag-150a-j Firmware
Mitsubishi te-50a
Mitsubishi te-200a Firmware
Mitsubishi ae-50a Firmware
Mitsubishi te-200a
Mitsubishi
Mitsubishi ae-50j Firmware
Mitsubishi ag-150a-a
Mitsubishi gb-50ada-j
Mitsubishi ag-150a-j
Mitsubishi g-150ad Firmware
Mitsubishi ew-50a Firmware
Mitsubishi ae-200a
Mitsubishi ae-200j Firmware
Mitsubishi g-150ad
Mitsubishi ae-200e Firmware
Mitsubishi ew-50j Firmware
Mitsubishi ae-50e Firmware
Mitsubishi eb-50gu-a
Mitsubishi tw-50a Firmware
Mitsubishi ae-50a
Mitsubishi gb-50a
Mitsubishi gb-50ada-j Firmware
Mitsubishi tw-50a
Mitsubishi ae-200e
Mitsubishi gb-50ada-a Firmware
Mitsubishi ae-200a Firmware
Mitsubishi eb-50gu-j
Mitsubishi ew-50e
Mitsubishi ae-50j

08 Jun 2022, 15:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-06-08 15:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-24296

Mitre link : CVE-2022-24296

CVE.ORG link : CVE-2022-24296


JSON object : View

Products Affected

mitsubishi

  • ae-50j
  • ag-150a-a
  • te-50a_firmware
  • te-200a_firmware
  • te-50a
  • ae-200j
  • ae-50e
  • ae-200a_firmware
  • gb-50ada-j_firmware
  • gb-50a_firmware
  • ae-50j_firmware
  • ew-50j_firmware
  • ae-50e_firmware
  • ew-50a_firmware
  • ew-50e_firmware
  • g-150ad_firmware
  • tw-50a
  • ew-50e
  • gb-50ada-a_firmware
  • ae-200j_firmware
  • eb-50gu-a
  • ae-200a
  • tw-50a_firmware
  • te-200a
  • g-150ad
  • gb-50ada-j
  • ae-50a
  • eb-50gu-j
  • gb-50ada-a
  • gb-50a
  • ae-200e
  • ag-150a-j_firmware
  • ae-200e_firmware
  • ag-150a-j
  • eb-50gu-a_firmware
  • ag-150a-a_firmware
  • eb-50gu-j_firmware
  • ew-50j
  • ae-50a_firmware
  • ew-50a
CWE
CWE-327

Use of a Broken or Risky Cryptographic Algorithm