Authentication Bypass by Spoofing in Mitsubishi Electric products - CVE-2022-40269

 

Authentication Bypass by Spoofing in Mitsubishi Electric products - CVE-2022-40269

Published: February 3, 2023


Vulnerability identifier: #VU71793
CSH Severity: Medium
CVSS v4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-40269
CWE-ID: CWE-290
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass authentication process.

The vulnerability exists due to an error in when processing authentication requests. A remote attacker can impersonate legitimate users by abusing inappropriate HTML attributes or cause users' browsers to disclose sensitive information.


Affected software

GOT2000 GT27 model
GOT2000 GT25 model
GT SoftGOT2000

How to mitigate CVE-2022-40269

Install updates from vendor's website.

GOT2000 GT27 model - update to 01.48.000
GOT2000 GT25 model - update to 01.48.000
GT SoftGOT2000 - update to 1.290C

External References

Related Security Bulletins