ID

VAR-202211-0444


CVE

CVE-2022-33322


TITLE

Mitsubishi Electric consumer electronics products Cross-site scripting vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-202211-2339

DESCRIPTION

Cross-site scripting vulnerability in Mitsubishi Electric consumer electronics products (Air Conditioning, Wi-Fi Interface, Refrigerator, HEMS adapter, Remote control with Wi-Fi Interface, BATHROOM THERMO VENTILATOR, Rice cooker, Mitsubishi Electric HEMS control adapter, Energy Recovery Ventilator, Smart Switch and Air Purifier) allows a remote unauthenticated attacker to execute an malicious script on a user's browser to disclose information, etc. The wide range of models/versions of Mitsubishi Electric consumer electronics products are affected by this vulnerability. As for the affected product models/versions, see the Mitsubishi Electric's advisory which is listed in [References] section.

Trust: 1.0

sources: NVD: CVE-2022-33322

IOT TAXONOMY

category:['home & office device']sub_category:smart home device

Trust: 0.1

sources: OTHER: None

AFFECTED PRODUCTS

vendor:mitsubishielectricmodel:msz-ay25\/35\/42\/50vgkp-et1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ft25\/35\/50vgk-sc2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-bt20\/25\/35\/50vgk-et2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ef22\/25\/35\/42\/50vgkb-er1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ef18\/22\/25\/35\/42\/50vgks-e1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ap15\/20\/25\/35\/42\/50\/60\/71vgk-e2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ap25\/35\/42\/50vgk-e7scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ap25\/35\/42\/50\/60\/71vgk-et3scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-bt20\/25\/35\/50vgk-e3scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ef22\/25\/35\/42\/50vgkw-et2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ap15\/20\/25\/35\/42\/50\/60\/71vgk-et2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-hr25\/35\/42\/50\/60\/71vfk-er1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ap22\/25\/35\/42\/50\/60\/71\/80vgkd-a2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln18\/25\/35\/50\/60vg2r-e2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln25\/35\/50\/60vg2v-et3scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-exa09\/12vakscope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ap25\/35\/42\/50\/60\/71vgk-e3scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln25\/35\/50\/60vg2b-er2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ap25\/35\/42\/50\/60\/71vgk-er3scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ap25\/35\/42\/50vgk-en2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ef22\/25\/35\/42\/50vgkb-et1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ef18\/22\/25\/35\/42\/50vgkb-e1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln25\/35\/50\/60vg2v-er3scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ap25\/35\/42\/50vgk-e1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ky09\/12\/18vfkscope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ef22\/25\/35\/42\/50vgkb-a1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ap25\/35\/42\/50vgk-e8scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msy-gp10\/13\/15\/18\/20\/24vfk-sg1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ap25\/35\/42\/50vgk-er1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ef22\/25\/35\/42\/50vgkb-et2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln25\/35\/50\/60vg2r-er3scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln25\/35\/50vg2b-en2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ef22\/25\/35\/42\/50vgkb-er2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ap25\/35\/42\/50vgk-en3scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ef18\/22\/25\/35\/42\/50vgks-e2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-hr25\/35\/42\/50\/60\/71vfk-e1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln18\/25\/35\/50\/60vg2w-e3scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ap15\/20\/25\/35\/42\/50\/60\/71vgk-er2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ay25\/35\/42\/50vgk-sc1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln18\/25\/35\/50\/60vg2r-e3scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln25\/35\/50\/60vg2r-a2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-rw25\/35\/50vg-et1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-rw25\/35\/50vg-sc1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln18\/25\/35\/50\/60vg2b-e3scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln18\/25\/35\/50\/60vg2w-e2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ef22\/25\/35\/42\/50vgks-a1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ft25\/35\/50vgk-et1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:mac-588if-escope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ay25\/35\/42\/50vgkp-sc1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:mfz-gxt50\/60\/73vfkscope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln18\/25\/35\/50\/60vg2v-e3scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-bt20\/25\/35\/50vgk-et3scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ap25\/35\/42\/50vgk-en1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-bt20\/25\/35\/50vgk-et1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-gzy09\/12\/18vfkscope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ef18\/22\/25\/35\/42\/50vgkb-e2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ay25\/35\/42\/50vgkp-e6scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ay25\/35\/42\/50vgk-e6scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ef22\/25\/35\/42\/50vgks-er1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:ma-ew85s-escope:lteversion:80.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln25\/35\/50\/60vg2r-et2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-bt20\/25\/35\/50vgk-e2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln25\/35\/50\/60vg2b-et3scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln25\/35\/50\/60vg2r-et3scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln25\/35\/50\/60vg2v-et2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:mac-587if2-escope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ef22\/25\/35\/42\/50vgkw-a1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln25\/35\/50\/60vg2b-er3scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ef22\/25\/35\/42\/50vgkw-er2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln25\/35\/50\/60vg2b-et2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln25\/35\/50\/60vg2b-a2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln25\/35\/50vg2v-sc1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-wx18\/20\/25vfkscope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-zy09\/12\/18vfkscope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:mfz-xt50\/60vfkscope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ay25\/35\/42\/50vgk-er1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln25\/35\/50\/60vg2r-er2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-eza09\/12vakscope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln25\/35\/50\/60vg2v-er2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:ma-ew85s-ukscope:lteversion:80.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln18\/25\/35\/50\/60vg2b-e2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ay25\/35\/42\/50vgk-et1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ef22\/25\/35\/42\/50vgkw-er1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ft25\/35\/50vgk-sc1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln18\/25\/35\/50vg2w-sc1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msxy-fp05\/07\/10\/13\/18\/20\/24vgk-sg1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ft25\/35\/50vgk-e1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln25\/35\/50\/60vg2w-et3scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-rw25\/35\/50vg-er1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-hr25\/35\/42\/50vfk-e6scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln18\/25\/35\/50\/60vg2w-er2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ay25\/35\/42\/50vgk-e1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:mac-507if-escope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ay25\/35\/42\/50vgkp-er1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln25\/35\/50\/60vg2v-a2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln18\/25\/35\/50\/60vg2w-et2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ap22\/25\/35\/42\/50\/61\/70\/80vgkd-a1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-bt20\/25\/35\/50vgk-e1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln25\/35\/50\/60vg2w-er3scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln25\/35\/50vg2w-en2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-rw25\/35\/50vg-e1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ef22\/25\/35\/42\/50vgkw-et1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-hr25\/35\/42\/50\/60\/71vfk-et1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:mac-587if-escope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-bt20\/25\/35\/50vgk-er1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln25\/35\/50vg2r-en2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ef22\/25\/35\/42\/50vgks-et1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln25\/35\/50vg2v-en2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ef18\/22\/25\/35\/42\/50vgkw-e1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ef22\/25\/35\/42\/50vgks-et2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:s-mac-002ifscope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ap25\/35\/42\/50vgk-et1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ft25\/35\/50vgk-e2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln18\/25\/35\/50\/60vg2v-e2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-bt20\/25\/35\/50vgk-er2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ef18\/22\/25\/35\/42\/50vgkw-e2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln25\/35\/50vg2r-sc1scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ef22\/25\/35\/42\/50vgks-er2scope:lteversion:35.00

Trust: 1.0

vendor:mitsubishielectricmodel:msz-ln25\/35\/50vg2b-sc1scope:lteversion:35.00

Trust: 1.0

sources: NVD: CVE-2022-33322

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2022-33322
value: MEDIUM

Trust: 1.0

134c704f-9b21-4f2e-91b3-4a467353bcc0: CVE-2022-33322
value: MEDIUM

Trust: 1.0

CNNVD: CNNVD-202211-2339
value: MEDIUM

Trust: 0.6

nvd@nist.gov: CVE-2022-33322
baseSeverity: MEDIUM
baseScore: 6.1
vectorString: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: CHANGED
confidentialityImpact: LOW
integrityImpact: LOW
availabilityImpact: NONE
exploitabilityScore: 2.8
impactScore: 2.7
version: 3.1

Trust: 2.0

sources: CNNVD: CNNVD-202211-2339 // NVD: CVE-2022-33322 // NVD: CVE-2022-33322

PROBLEMTYPE DATA

problemtype:CWE-79

Trust: 1.0

sources: NVD: CVE-2022-33322

THREAT TYPE

remote

Trust: 0.6

sources: CNNVD: CNNVD-202211-2339

TYPE

XSS

Trust: 0.6

sources: CNNVD: CNNVD-202211-2339

PATCH

title:Mitsubishi Electric consumer electronics products Fixes for cross-site scripting vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqById.tag?id=214622

Trust: 0.6

sources: CNNVD: CNNVD-202211-2339

EXTERNAL IDS

db:NVDid:CVE-2022-33322

Trust: 1.7

db:JVNid:JVNVU96767562

Trust: 1.6

db:CNNVDid:CNNVD-202211-2339

Trust: 0.6

db:OTHERid:NONE

Trust: 0.1

sources: OTHER: None // CNNVD: CNNVD-202211-2339 // NVD: CVE-2022-33322

REFERENCES

url:https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2022-011_en.pdf

Trust: 1.6

url:https://www.mitsubishielectric.co.jp/psirt/vulnerability/pdf/2022-011.pdf

Trust: 1.6

url:https://jvn.jp/vu/jvnvu96767562/index.html

Trust: 1.6

url:https://cxsecurity.com/cveshow/cve-2022-33322/

Trust: 0.6

url:https://ieeexplore.ieee.org/abstract/document/10769424

Trust: 0.1

sources: OTHER: None // CNNVD: CNNVD-202211-2339 // NVD: CVE-2022-33322

SOURCES

db:OTHERid: -
db:CNNVDid:CNNVD-202211-2339
db:NVDid:CVE-2022-33322

LAST UPDATE DATE

2025-05-01T21:19:20.047000+00:00


SOURCES UPDATE DATE

db:CNNVDid:CNNVD-202211-2339date:2022-11-23T00:00:00
db:NVDid:CVE-2022-33322date:2025-05-01T15:15:55.120

SOURCES RELEASE DATE

db:CNNVDid:CNNVD-202211-2339date:2022-11-08T00:00:00
db:NVDid:CVE-2022-33322date:2022-11-08T20:15:11.017