Vulnerabilities > CVE-2008-1546 - Remote Authentication Bypass vulnerability in Mitsubishi Electric GB 50/50A

047910
CVSS 7.8 - HIGH
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
NONE
Availability impact
COMPLETE
network
low complexity
mitsubishi-electric

Summary

servlet/MIMEReceiveServlet in the web controller for Mitsubishi Electric GB-50 and GB-50A air-conditioning control systems allows remote attackers to cause a denial of service (air-conditioning outage) via an XML document containing a setRequest command.

Vulnerable Configurations

Part Description Count
Hardware
Mitsubishi_Electric
2