
Severity
High
Analysis Summary
CVE-2022-24296
Mitsubishi Electric products could allow a remote attacker to obtain sensitive information, caused by the use of cryptographically weak algorithm. By sniffing encrypted communications, an attacker could exploit this vulnerability to obtain encrypted message contents from the air conditioning systems.
Impact
- Information Disclosure
Indicators Of Compromise
CVE
- CVE-2022-24296
Affected Vendors
Mitsubishi Electric
Affected Products
- Mitsubishi Electric G-150AD 3.21
- Mitsubishi Electric AG-150A-A 3.21
- Mitsubishi Electric AG-150A-J 3.21
- Mitsubishi Electric GB-50AD 3.21
Remediation
Refer to Mitsubishi Electric Web site for patch, upgrade or suggested workaround information.