CVE Published: 08/11/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: Mitsubishi |
Vendor: Mitsubishi Electric Corporation |
Product: Air Conditioning MSZ-FD40/56/63/71/8022S Status : PUBLISHED
CVE-2022-33322 Description
Cross-site scripting vulnerability in Mitsubishi Electric consumer electronics products (Air Conditioning, Wi-Fi Interface, Refrigerator, HEMS adapter, Remote control with Wi-Fi Interface, BATHROOM THERMO VENTILATOR, Rice cooker, Mitsubishi Electric HEMS control adapter, Energy Recovery Ventilator, Smart Switch and Air Purifier) allows a remote unauthenticated attacker to execute an malicious script on a user\'s browser to disclose information, etc. The wide range of models/versions of Mitsubishi Electric consumer electronics products are affected by this vulnerability. As for the affected product models/versions, see the Mitsubishi Electric\'s advisory which is listed in [References] section.