Vulnerability Description
Improper Restriction of XML External Entity Reference vulnerability in Mitsubishi Electric Air Conditioning System/Centralized Controllers (G-50A Ver.3.35 and prior, GB-50A Ver.3.35 and prior, GB-24A Ver.9.11 and prior, AG-150A-A Ver.3.20 and prior, AG-150A-J Ver.3.20 and prior, GB-50ADA-A Ver.3.20 and prior, GB-50ADA-J Ver.3.20 and prior, EB-50GU-A Ver 7.09 and prior, EB-50GU-J Ver 7.09 and prior, AE-200A Ver 7.93 and prior, AE-200E Ver 7.93 and prior, AE-50A Ver 7.93 and prior, AE-50E Ver 7.93 and prior, EW-50A Ver 7.93 and prior, EW-50E Ver 7.93 and prior, TE-200A Ver 7.93 and prior, TE-50A Ver 7.93 and prior, TW-50A Ver 7.93 and prior, CMS-RMD-J Ver.1.30 and prior), Air Conditioning System/Expansion Controllers (PAC-YG50ECA Ver.2.20 and prior) and Air Conditioning System/BM adapter(BAC-HD150 Ver.2.21 and prior) allows a remote unauthenticated attacker to disclose some of data in the air conditioning system or cause a DoS condition by sending specially crafted packets.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mitsubishi | G-50A Firmware | >= 2.50, <= 3.35 |
| Mitsubishi | G-50A | - |
| Mitsubishi | Gb-50A Firmware | >= 2.50, <= 3.35 |
| Mitsubishi | Gb-50A | - |
| Mitsubishi | Ag-150A-A Firmware | <= 3.20 |
| Mitsubishi | Ag-150A-A | - |
| Mitsubishi | Ag-150A-J Firmware | <= 3.20 |
| Mitsubishi | Ag-150A-J | - |
| Mitsubishi | Gb-50Ada-A Firmware | <= 3.20 |
| Mitsubishi | Gb-50Ada-A | - |
| Mitsubishi | Gb-50Ada-J Firmware | <= 3.20 |
| Mitsubishi | Gb-50Ada-J | - |
| Mitsubishi | Eb-50Gu-A Firmware | <= 7.09 |
| Mitsubishi | Eb-50Gu-A | - |
| Mitsubishi | Eb-50Gu-J Firmware | <= 7.09 |
| Mitsubishi | Eb-50Gu-J | - |
| Mitsubishi | Ae-200A Firmware | <= 7.93 |
| Mitsubishi | Ae-200A | - |
| Mitsubishi | Ae-200E Firmware | <= 7.93 |
| Mitsubishi | Ae-200E | - |
Related Weaknesses (CWE)
References
- https://jvn.jp/vu/JVNVU93086468/index.htmlThird Party Advisory
- https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2021-005_en.pdfVendor Advisory
- https://jvn.jp/vu/JVNVU93086468/index.htmlThird Party Advisory
- https://www.mitsubishielectric.com/en/psirt/vulnerability/pdf/2021-005_en.pdfVendor Advisory
FAQ
What is CVE-2021-20595?
CVE-2021-20595 is a vulnerability with a CVSS score of 8.2 (HIGH). Improper Restriction of XML External Entity Reference vulnerability in Mitsubishi Electric Air Conditioning System/Centralized Controllers (G-50A Ver.3.35 and prior, GB-50A Ver.3.35 and prior, GB-24A ...
How severe is CVE-2021-20595?
CVE-2021-20595 has been rated HIGH with a CVSS base score of 8.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-20595?
Check the references section above for vendor advisories and patch information. Affected products include: Mitsubishi G-50A Firmware, Mitsubishi G-50A, Mitsubishi Gb-50A Firmware, Mitsubishi Gb-50A, Mitsubishi Ag-150A-A Firmware.