CVE-2022-38355

EUVD-2022-40944
Daikin SVMPC1 version 2.1.22 and prior and SVMPC2 version 1.2.3 and prior are vulnerable to 

attackers with access to the local area network (LAN) to disclose sensitive information stored by the affected product without requiring authentication.

ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
icscertCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 29%
Affected Products (NVD)
VendorProductVersion
daikinlatamsvmpc1
𝑥
≤ 2.1.22
daikinlatamsvmpc2
𝑥
≤ 1.2.3
𝑥
= Vulnerable software versions