CVE Feed

    Dashboard / CVE / CVE-2021-20595

    CVE-2021-20595

    Improper Restriction of XML External Entity Reference vulnerability in Mitsubishi Electric Air Conditioning System/Centralized Controllers (G-50A Ver.3.35 and prior, GB-50A Ver.3.35 and prior, GB-24A Ver.9.11 and prior, AG-150A-A Ver.3.20 and prior, AG-150A-J Ver.3.20 and prior, GB-50ADA-A Ver.3.20 and prior, GB-50ADA-J Ver.3.20 and prior, EB-50GU-A Ver 7.09 and prior, EB-50GU-J Ver 7.09 and prior, AE-200A Ver 7.93 and prior, AE-200E Ver 7.93 and prior, AE-50A Ver 7.93 and prior, AE-50E Ver 7.93 and prior, EW-50A Ver 7.93 and prior, EW-50E Ver 7.93 and prior, TE-200A Ver 7.93 and prior, TE-50A Ver 7.93 and prior, TW-50A Ver 7.93 and prior, CMS-RMD-J Ver.1.30 and prior), Air Conditioning System/Expansion Controllers (PAC-YG50ECA Ver.2.20 and prior) and Air Conditioning System/BM adapter(BAC-HD150 Ver.2.21 and prior) allows a remote unauthenticated attacker to disclose some of data in the air conditioning system or cause a DoS condition by sending specially crafted packets.

    Published:Jul 13, 2021
    Last Modified:Nov 21, 2024
    EPS:Jul 13, 2021
    EPSS Score:0.00154
    CVSS Score:8.2

    Affected Products

    Vendor
    Mitsubishi
    Product
    Ae-200a
    Vendor
    Mitsubishi
    Product
    Ae-200a Firmware
    Vendor
    Mitsubishi
    Product
    Ae-200e
    Vendor
    Mitsubishi
    Product
    Ae-200e Firmware
    Vendor
    Mitsubishi
    Product
    Ae-50a
    Vendor
    Mitsubishi
    Product
    Ae-50a Firmware
    Vendor
    Mitsubishi
    Product
    Ae-50e
    Vendor
    Mitsubishi
    Product
    Ae-50e Firmware
    Vendor
    Mitsubishi
    Product
    Ag-150a-a
    Vendor
    Mitsubishi
    Product
    Ag-150a-a Firmware
    Vendor
    Mitsubishi
    Product
    Ag-150a-j
    Vendor
    Mitsubishi
    Product
    Ag-150a-j Firmware
    Vendor
    Mitsubishi
    Product
    Cms-rmd-j
    Vendor
    Mitsubishi
    Product
    Cms-rmd-j Firmware
    Vendor
    Mitsubishi
    Product
    Eb-50gu-a
    Vendor
    Mitsubishi
    Product
    Eb-50gu-a Firmware
    Vendor
    Mitsubishi
    Product
    Eb-50gu-j
    Vendor
    Mitsubishi
    Product
    Eb-50gu-j Firmware
    Vendor
    Mitsubishi
    Product
    Ew-50a
    Vendor
    Mitsubishi
    Product
    Ew-50a Firmware
    Vendor
    Mitsubishi
    Product
    Ew-50e
    Vendor
    Mitsubishi
    Product
    Ew-50e Firmware
    Vendor
    Mitsubishi
    Product
    G-50a
    Vendor
    Mitsubishi
    Product
    G-50a Firmware
    Vendor
    Mitsubishi
    Product
    Gb-50a
    Vendor
    Mitsubishi
    Product
    Gb-50a Firmware
    Vendor
    Mitsubishi
    Product
    Gb-50ada-a
    Vendor
    Mitsubishi
    Product
    Gb-50ada-a Firmware
    Vendor
    Mitsubishi
    Product
    Gb-50ada-j
    Vendor
    Mitsubishi
    Product
    Gb-50ada-j Firmware
    Vendor
    Mitsubishi
    Product
    Pac-yg50eca
    Vendor
    Mitsubishi
    Product
    Pac-yg50eca Firmware
    Vendor
    Mitsubishi
    Product
    Te-200a
    Vendor
    Mitsubishi
    Product
    Te-200a Firmware
    Vendor
    Mitsubishi
    Product
    Te-50a
    Vendor
    Mitsubishi
    Product
    Te-50a Firmware
    Vendor
    Mitsubishi
    Product
    Tw-50a
    Vendor
    Mitsubishi
    Product
    Tw-50a Firmware

    Exploits

    No exploit reference

    Common Attack Pattern Enumeration and Classification (CAPEC)

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High