First published: Tue Jul 13 2021(Updated: )
Improper Restriction of XML External Entity Reference vulnerability in Mitsubishi Electric Air Conditioning System/Centralized Controllers (G-50A Ver.3.35 and prior, GB-50A Ver.3.35 and prior, GB-24A Ver.9.11 and prior, AG-150A-A Ver.3.20 and prior, AG-150A-J Ver.3.20 and prior, GB-50ADA-A Ver.3.20 and prior, GB-50ADA-J Ver.3.20 and prior, EB-50GU-A Ver 7.09 and prior, EB-50GU-J Ver 7.09 and prior, AE-200A Ver 7.93 and prior, AE-200E Ver 7.93 and prior, AE-50A Ver 7.93 and prior, AE-50E Ver 7.93 and prior, EW-50A Ver 7.93 and prior, EW-50E Ver 7.93 and prior, TE-200A Ver 7.93 and prior, TE-50A Ver 7.93 and prior, TW-50A Ver 7.93 and prior, CMS-RMD-J Ver.1.30 and prior), Air Conditioning System/Expansion Controllers (PAC-YG50ECA Ver.2.20 and prior) and Air Conditioning System/BM adapter(BAC-HD150 Ver.2.21 and prior) allows a remote unauthenticated attacker to disclose some of data in the air conditioning system or cause a DoS condition by sending specially crafted packets.
Credit: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
Affected Software | Affected Version | How to fix |
---|---|---|
Mitsubishi G-50a | >=2.50<=3.35 | |
Mitsubishi G-50a Firmware | ||
Mitsubishi GB-50A | >=2.50<=3.35 | |
Mitsubishi GB-50A | ||
Mitsubishi Ag-150a-a | <=3.20 | |
Mitsubishi Ag-150a-a Firmware | ||
Mitsubishi AG-150A-J | <=3.20 | |
Mitsubishi AG-150A-J | ||
Mitsubishi Gb-50ada-a | <=3.20 | |
Mitsubishi Gb-50ada-a Firmware | ||
Mitsubishi Gb-50ada-j Firmware | <=3.20 | |
Mitsubishi Gb-50ada-j Firmware | ||
Mitsubishi Eb-50gu-a | <=7.09 | |
Mitsubishi Eb-50gu-a Firmware | ||
Mitsubishi Eb-50gu-j | <=7.09 | |
Mitsubishi Eb-50gu-j Firmware | ||
Mitsubishi Te-200a | <=7.93 | |
Mitsubishi Ae-200a Firmware | ||
Mitsubishi Ae-200e | <=7.93 | |
Mitsubishi Ae-200e Firmware | ||
Mitsubishi Ae-50a | <=7.93 | |
Mitsubishi G-50a Firmware | ||
Mitsubishi Ae-50a | <=7.93 | |
Mitsubishi Ae-50e Firmware | ||
Mitsubishi Ew-50a Firmware | <=7.93 | |
Mitsubishi Ew-50a Firmware | ||
Mitsubishi Ew-50e | <=7.93 | |
Mitsubishi Ew-50e Firmware | ||
Mitsubishi Te-200a | <=7.93 | |
Mitsubishi Te-200a Firmware | ||
Mitsubishi Te-200a | <=7.93 | |
Mitsubishi Te-50a Firmware | ||
Mitsubishi Tw-50a Firmware | <=7.93 | |
Mitsubishi Tw-50a Firmware | ||
Mitsubishi Cms-rmd-j Firmware | <=1.30 | |
Mitsubishi Cms-rmd-j Firmware | ||
Mitsubishi Pac-yg50eca Firmware | <=2.20 | |
Mitsubishi Pac-yg50eca Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2021-20595.
The severity of CVE-2021-20595 is high with a CVSS score of 8.2.
The affected software versions are Mitsubishi Electric Air Conditioning System/Centralized Controllers G-50A Ver.3.35 and prior, GB-50A Ver.3.35 and prior, GB-24A Ver.9.11 and prior, AG-150A-A Ver.3.20 and prior, AG-150A-J Ver.3.20 and prior, GB-50ADA-A Ver.3.20 and prior, and GB-50ADA-J Ver.3.20 and prior.
CVE-2021-20595 allows attackers to exploit an XML External Entity (XXE) vulnerability in the affected software.
Yes, Mitsubishi Electric has released a security advisory with mitigation measures for CVE-2021-20595. Please refer to the vendor's advisory for more information.