Incorrect Implementation of Authentication Algorithm in Mitsubishi Electric Air Conditioning System/Centralized Controllers (G-50A Ver.2.50 to Ver. 3.35, GB-50A Ver.2.50 to Ver. 3.35, AG-150A-A Ver.3.20 and prior, AG-150A-J Ver.3.20 and prior, GB-50ADA-A Ver.3.20 and prior, GB-50ADA-J Ver.3.20 and prior, EB-50GU-A Ver 7.09 and prior, EB-50GU-J Ver 7.09 and prior, AE-200A Ver 7.93 and prior, AE-200E Ver 7.93 and prior, AE-50A Ver 7.93 and prior, AE-50E Ver 7.93 and prior, EW-50A Ver 7.93 and prior, EW-50E Ver 7.93 and prior, TE-200A Ver 7.93 and prior, TE-50A Ver 7.93 and prior, TW-50A Ver 7.93 and prior, CMS-RMD-J Ver.1.30 and prior) and Air Conditioning System/Expansion Controllers (PAC-YG50ECA Ver.2.20 and prior) allows a remote authenticated attacker to impersonate administrators to disclose configuration information of the air conditioning system and tamper information (e.g. operation information and configuration of air conditioning system) by exploiting this vulnerability.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Mitsubishi
Subscribe
|
Ae-200a
Subscribe
Ae-200a Firmware
Subscribe
Ae-200e
Subscribe
Ae-200e Firmware
Subscribe
Ae-50a
Subscribe
Ae-50a Firmware
Subscribe
Ae-50e
Subscribe
Ae-50e Firmware
Subscribe
Ag-150a-a
Subscribe
Ag-150a-a Firmware
Subscribe
Ag-150a-j
Subscribe
Ag-150a-j Firmware
Subscribe
Cms-rmd-j
Subscribe
Cms-rmd-j Firmware
Subscribe
Eb-50gu-a
Subscribe
Eb-50gu-a Firmware
Subscribe
Eb-50gu-j
Subscribe
Eb-50gu-j Firmware
Subscribe
Ew-50a
Subscribe
Ew-50a Firmware
Subscribe
Ew-50e
Subscribe
Ew-50e Firmware
Subscribe
G-50a
Subscribe
G-50a Firmware
Subscribe
Gb-50a
Subscribe
Gb-50a Firmware
Subscribe
Gb-50ada-a
Subscribe
Gb-50ada-a Firmware
Subscribe
Gb-50ada-j
Subscribe
Gb-50ada-j Firmware
Subscribe
Pac-yg50eca
Subscribe
Pac-yg50eca Firmware
Subscribe
Te-200a
Subscribe
Te-200a Firmware
Subscribe
Te-50a
Subscribe
Te-50a Firmware
Subscribe
Tw-50a
Subscribe
Tw-50a Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-8011 | Incorrect Implementation of Authentication Algorithm in Mitsubishi Electric Air Conditioning System/Centralized Controllers (G-50A Ver.2.50 to Ver. 3.35, GB-50A Ver.2.50 to Ver. 3.35, AG-150A-A Ver.3.20 and prior, AG-150A-J Ver.3.20 and prior, GB-50ADA-A Ver.3.20 and prior, GB-50ADA-J Ver.3.20 and prior, EB-50GU-A Ver 7.09 and prior, EB-50GU-J Ver 7.09 and prior, AE-200A Ver 7.93 and prior, AE-200E Ver 7.93 and prior, AE-50A Ver 7.93 and prior, AE-50E Ver 7.93 and prior, EW-50A Ver 7.93 and prior, EW-50E Ver 7.93 and prior, TE-200A Ver 7.93 and prior, TE-50A Ver 7.93 and prior, TW-50A Ver 7.93 and prior, CMS-RMD-J Ver.1.30 and prior) and Air Conditioning System/Expansion Controllers (PAC-YG50ECA Ver.2.20 and prior) allows a remote authenticated attacker to impersonate administrators to disclose configuration information of the air conditioning system and tamper information (e.g. operation information and configuration of air conditioning system) by exploiting this vulnerability. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Mitsubishi
Published:
Updated: 2024-08-03T17:45:44.715Z
Reserved: 2020-12-17T00:00:00
Link: CVE-2021-20593
No data.
Status : Modified
Published: 2021-07-13T14:15:08.410
Modified: 2024-11-21T05:46:50.477
Link: CVE-2021-20593
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD