Authentication Bypass by Spoofing in Mitsubishi Electric products - CVE-2022-40269
Published: February 3, 2023
Vulnerability identifier: #VU71793
CSH Severity: Medium
CVSS v4: 7.4 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-40269
CWE-ID: CWE-290
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests. A remote attacker can impersonate legitimate users by abusing inappropriate HTML attributes or cause users' browsers to disclose sensitive information.
Affected software
GOT2000 GT27 model
GOT2000 GT25 model
GT SoftGOT2000
GOT2000 GT25 model
GT SoftGOT2000
How to mitigate CVE-2022-40269
Install updates from vendor's website.
GOT2000 GT27 model - update to 01.48.000
GOT2000 GT25 model - update to 01.48.000
GT SoftGOT2000 - update to 1.290C
GOT2000 GT25 model - update to 01.48.000
GT SoftGOT2000 - update to 1.290C