CVE-2022-24296: High severity mitsubishi te-200a vulnerability

Published Jun 8, 2022
·
Updated

Use of a Broken or Risky Cryptographic Algorithm vulnerability in Air Conditioning System G-150AD Ver. 3.21 and prior, Air Conditioning System AG-150A-A Ver. 3.21 and prior, Air Conditioning System AG-150A-J Ver. 3.21 and prior, Air Conditioning System GB-50AD Ver. 3.21 and prior, Air Conditioning System GB-50ADA-A Ver. 3.21 and prior, Air Conditioning System GB-50ADA-J Ver. 3.21 and prior, Air Conditioning System EB-50GU-A Ver. 7.10 and prior, Air Conditioning System EB-50GU-J Ver. 7.10 and prior, Air Conditioning System AE-200J Ver. 7.97 and prior, Air Conditioning System AE-200A Ver. 7.97 and prior, Air Conditioning System AE-200E Ver. 7.97 and prior, Air Conditioning System AE-50J Ver. 7.97 and prior, Air Conditioning System AE-50A Ver. 7.97 and prior, Air Conditioning System AE-50E Ver. 7.97 and prior, Air Conditioning System EW-50J Ver. 7.97 and prior, Air Conditioning System EW-50A Ver. 7.97 and prior, Air Conditioning System EW-50E Ver. 7.97 and prior, Air Conditioning System TE-200A Ver. 7.97 and prior, Air Conditioning System TE-50A Ver. 7.97 and prior and Air Conditioning System TW-50A Ver. 7.97 and prior allows a remote unauthenticated attacker to cause a disclosure of encrypted message of the air conditioning systems by sniffing encrypted communications.

Affected Software

40 affected components
Mitsubishi Ae-200a Firmware<=7.97
Mitsubishi AE-200A
Mitsubishi Ae-200e Firmware<=7.97
Mitsubishi AE-200E
Mitsubishi Ae-200j Firmware<=7.97
Mitsubishi Ae-200j
Mitsubishi Ae-50a Firmware<=7.97
Mitsubishi AE-50A
Mitsubishi Ae-50e Firmware<=7.97
Mitsubishi AE-50E
Mitsubishi Ae-50j Firmware<=7.97
Mitsubishi Ae-50j
Mitsubishi Ag-150a-a Firmware<=3.21
Mitsubishi AG-150A-A
Mitsubishi Ag-150a-j Firmware<=3.21
Mitsubishi AG-150A-J
Mitsubishi Eb-50gu-a Firmware<=7.10
Mitsubishi EB-50GU-A
Mitsubishi Eb-50gu-j Firmware<=7.10
Mitsubishi EB-50GU-J
Mitsubishi Ew-50a Firmware<=7.97
Mitsubishi EW-50A
Mitsubishi Ew-50e Firmware<=7.97
Mitsubishi EW-50E
Mitsubishi Ew-50j Firmware<=7.97
Mitsubishi Ew-50j
Mitsubishi G-150ad Firmware<=3.21
Mitsubishi G-150ad
Mitsubishi Gb-50a Firmware<=3.21
Mitsubishi GB-50A
Mitsubishi Gb-50ada-a Firmware<=3.21
Mitsubishi GB-50ADA-A
Mitsubishi Gb-50ada-j Firmware<=3.21
Mitsubishi GB-50ADA-J
Mitsubishi Te-200a Firmware<=7.97
Mitsubishi TE-200A
Mitsubishi Te-50a Firmware<=7.97
Mitsubishi TE-50A
Mitsubishi Tw-50a Firmware<=7.97
Mitsubishi TW-50A

Event History

Jun 8, 2022
CVE Published
via MITRE·02:11 PM
Data Sourced
via MITRE·02:11 PM
DescriptionWeakness
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the vulnerability ID for the Use of a Broken or Risky Cryptographic Algorithm vulnerability in the Air Conditioning System?

The vulnerability ID for this issue is CVE-2022-24296.

2

What is the severity rating of CVE-2022-24296?

CVE-2022-24296 has a severity rating of 7.5 (High).

3

Which software versions are affected by CVE-2022-24296?

Air Conditioning System G-150AD Ver. 3.21 and prior, Air Conditioning System AG-150A-A Ver. 3.21 and prior, Air Conditioning System AG-150A-J Ver. 3.21 and prior, Air Conditioning System GB-50AD Ver. 3.21 and prior are affected by CVE-2022-24296.

4

How can I fix the Use of a Broken or Risky Cryptographic Algorithm vulnerability (CVE-2022-24296) in Mitsubishi Air Conditioning Systems?

To fix CVE-2022-24296, you should update the firmware of the affected Mitsubishi Air Conditioning Systems to a version beyond 3.21.

5

Where can I find more information about CVE-2022-24296?

You can find more information about CVE-2022-24296 in the following references: [link1], [link2], [link3].

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203