Description
Improper Restriction of XML External Entity Reference vulnerability in Mitsubishi Electric Air Conditioning System/Centralized Controllers (G-50A Ver.3.35 and prior, GB-50A Ver.3.35 and prior, GB-24A Ver.9.11 and prior, AG-150A-A Ver.3.20 and prior, AG-150A-J Ver.3.20 and prior, GB-50ADA-A Ver.3.20 and prior, GB-50ADA-J Ver.3.20 and prior, EB-50GU-A Ver 7.09 and prior, EB-50GU-J Ver 7.09 and prior, AE-200A Ver 7.93 and prior, AE-200E Ver 7.93 and prior, AE-50A Ver 7.93 and prior, AE-50E Ver 7.93 and prior, EW-50A Ver 7.93 and prior, EW-50E Ver 7.93 and prior, TE-200A Ver 7.93 and prior, TE-50A Ver 7.93 and prior, TW-50A Ver 7.93 and prior, CMS-RMD-J Ver.1.30 and prior), Air Conditioning System/Expansion Controllers (PAC-YG50ECA Ver.2.20 and prior) and Air Conditioning System/BM adapter(BAC-HD150 Ver.2.21 and prior) allows a remote unauthenticated attacker to disclose some of data in the air conditioning system or cause a DoS condition by sending specially crafted packets.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-8013 | Improper Restriction of XML External Entity Reference vulnerability in Mitsubishi Electric Air Conditioning System/Centralized Controllers (G-50A Ver.3.35 and prior, GB-50A Ver.3.35 and prior, GB-24A Ver.9.11 and prior, AG-150A-A Ver.3.20 and prior, AG-150A-J Ver.3.20 and prior, GB-50ADA-A Ver.3.20 and prior, GB-50ADA-J Ver.3.20 and prior, EB-50GU-A Ver 7.09 and prior, EB-50GU-J Ver 7.09 and prior, AE-200A Ver 7.93 and prior, AE-200E Ver 7.93 and prior, AE-50A Ver 7.93 and prior, AE-50E Ver 7.93 and prior, EW-50A Ver 7.93 and prior, EW-50E Ver 7.93 and prior, TE-200A Ver 7.93 and prior, TE-50A Ver 7.93 and prior, TW-50A Ver 7.93 and prior, CMS-RMD-J Ver.1.30 and prior), Air Conditioning System/Expansion Controllers (PAC-YG50ECA Ver.2.20 and prior) and Air Conditioning System/BM adapter(BAC-HD150 Ver.2.21 and prior) allows a remote unauthenticated attacker to disclose some of data in the air conditioning system or cause a DoS condition by sending specially crafted packets. |
References
History
No history.
Subscriptions
Mitsubishi
Subscribe
Ae-200a
Subscribe
Ae-200a Firmware
Subscribe
Ae-200e
Subscribe
Ae-200e Firmware
Subscribe
Ae-50a
Subscribe
Ae-50a Firmware
Subscribe
Ae-50e
Subscribe
Ae-50e Firmware
Subscribe
Ag-150a-a
Subscribe
Ag-150a-a Firmware
Subscribe
Ag-150a-j
Subscribe
Ag-150a-j Firmware
Subscribe
Cms-rmd-j
Subscribe
Cms-rmd-j Firmware
Subscribe
Eb-50gu-a
Subscribe
Eb-50gu-a Firmware
Subscribe
Eb-50gu-j
Subscribe
Eb-50gu-j Firmware
Subscribe
Ew-50a
Subscribe
Ew-50a Firmware
Subscribe
Ew-50e
Subscribe
Ew-50e Firmware
Subscribe
G-50a
Subscribe
G-50a Firmware
Subscribe
Gb-50a
Subscribe
Gb-50a Firmware
Subscribe
Gb-50ada-a
Subscribe
Gb-50ada-a Firmware
Subscribe
Gb-50ada-j
Subscribe
Gb-50ada-j Firmware
Subscribe
Pac-yg50eca
Subscribe
Pac-yg50eca Firmware
Subscribe
Te-200a
Subscribe
Te-200a Firmware
Subscribe
Te-50a
Subscribe
Te-50a Firmware
Subscribe
Tw-50a
Subscribe
Tw-50a Firmware
Subscribe
Status: PUBLISHED
Assigner: Mitsubishi
Published:
Updated: 2024-08-03T17:45:44.715Z
Reserved: 2020-12-17T00:00:00.000Z
Link: CVE-2021-20595
No data.
Status : Modified
Published: 2021-07-13T11:15:09.327
Modified: 2024-11-21T05:46:50.793
Link: CVE-2021-20595
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD