CVE-2021-20593
7.1
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
Exploitability: 2.8 / Impact: 4.2
Source: NVD
Description
Incorrect Implementation of Authentication Algorithm in Mitsubishi Electric Air Conditioning System/Centralized Controllers (G-50A Ver.2.50 to Ver. 3.35, GB-50A Ver.2.50 to Ver. 3.35, AG-150A-A Ver.3.20 and prior, AG-150A-J Ver.3.20 and prior, GB-50ADA-A Ver.3.20 and prior, GB-50ADA-J Ver.3.20 and prior, EB-50GU-A Ver 7.09 and prior, EB-50GU-J Ver 7.09 and prior, AE-200A Ver 7.93 and prior, AE-200E Ver 7.93 and prior, AE-50A Ver 7.93 and prior, AE-50E Ver 7.93 and prior, EW-50A Ver 7.93 and prior, EW-50E Ver 7.93 and prior, TE-200A Ver 7.93 and prior, TE-50A Ver 7.93 and prior, TW-50A Ver 7.93 and prior, CMS-RMD-J Ver.1.30 and prior) and Air Conditioning System/Expansion Controllers (PAC-YG50ECA Ver.2.20 and prior) allows a remote authenticated attacker to impersonate administrators to disclose configuration information of the air conditioning system and tamper information (e.g. operation information and configuration of air conditioning system) by exploiting this vulnerability.
Affected (19)
Products: Mitsubishi: G 50a Firmware, Gb 50a Firmware, Ag 150a A Firmware, Ag 150a J Firmware, Gb 50ada A Firmware, Gb 50ada J Firmware, Eb 50gu A Firmware, Eb 50gu J Firmware, Ae 200a Firmware, Ae 200e Firmware, Ae 50a Firmware, Ae 50e Firmware, Ew 50a Firmware, Ew 50e Firmware, Te 200a Firmware, Te 50a Firmware, Tw 50a Firmware, Cms Rmd J Firmware, Pac Yg50eca Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.50 to 3.35 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi G 50a | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| From 2.50 to 3.35 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Gb 50a | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.20 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Ag 150a A | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.20 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Ag 150a J | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.20 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Gb 50ada A | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 3.20 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Gb 50ada J | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 7.09 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Eb 50gu A | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 7.09 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Eb 50gu J | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 7.93 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Ae 200a | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 7.93 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Ae 200e | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 7.93 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Ae 50a | All versions |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 7.93 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Ae 50e | All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 7.93 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Ew 50a | All versions |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 7.93 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Ew 50e | All versions |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 7.93 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Te 200a | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 7.93 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Te 50a | All versions |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 7.93 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Tw 50a | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 1.30 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Cms Rmd J | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Up to 2.20 |
| Running on/with | Platform Versions |
|---|---|
Mitsubishi Pac Yg50eca | All versions |
References (4)
Source: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
Third Party Advisory
Source: Mitsubishielectric.Psirt@yd.MitsubishiElectric.co.jp
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.