You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2025-3699
About this tag
CVE-2025-3699 is a critical missing authentication vulnerability affecting multiple Mitsubishi Electric air conditioning controllers, as documented by CISA. With a CVSS v4 base score of 9.3, this flaw can allow attackers to bypass authentication, potentially disrupting building automation systems and threatening operational safety in commercial and critical infrastructure environments. Discussions on WindowsForum cover the technical details, risk assessment, and remediation strategies for this vulnerability, emphasizing its impact on industrial control systems and the importance of applying vendor-supplied patches and mitigations. The tag also relates to broader CISA advisories on ICS and medical device vulnerabilities.
CISA’s August 21, 2025 advisory bundle added three urgent entries to the growing list of industrial control system (ICS) and medical-device vulnerabilities security teams must treat as high priority this month. The agency published advisories for a denial-of-service vector in the Mitsubishi...
air conditioning controllers
cisa
cve-2025-3699
cve-2025-54551
cve-2025-5514
denial of service
fujifilm
ics
industrial control systems
ip filtering
medical devices
melsec iq-f
mitsubishi electric
network segmentation
patch management
security bypass
synapse
vulnerability
web interface
Few cybersecurity issues generate as much alarm—or as many practical ramifications—as those affecting building automation and industrial control systems. This has once again been underscored by a recent vulnerability uncovered in Mitsubishi Electric air conditioning systems, outlined by the...