8.5

CVE-2021-20595

Improper Restriction of XML External Entity Reference vulnerability in Mitsubishi Electric Air Conditioning System/Centralized Controllers (G-50A Ver.3.35 and prior, GB-50A Ver.3.35 and prior, GB-24A Ver.9.11 and prior, AG-150A-A Ver.3.20 and prior, AG-150A-J Ver.3.20 and prior, GB-50ADA-A Ver.3.20 and prior, GB-50ADA-J Ver.3.20 and prior, EB-50GU-A Ver 7.09 and prior, EB-50GU-J Ver 7.09 and prior, AE-200A Ver 7.93 and prior, AE-200E Ver 7.93 and prior, AE-50A Ver 7.93 and prior, AE-50E Ver 7.93 and prior, EW-50A Ver 7.93 and prior, EW-50E Ver 7.93 and prior, TE-200A Ver 7.93 and prior, TE-50A Ver 7.93 and prior, TW-50A Ver 7.93 and prior, CMS-RMD-J Ver.1.30 and prior), Air Conditioning System/Expansion Controllers (PAC-YG50ECA Ver.2.20 and prior) and Air Conditioning System/BM adapter(BAC-HD150 Ver.2.21 and prior) allows a remote unauthenticated attacker to disclose some of data in the air conditioning system or cause a DoS condition by sending specially crafted packets.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MitsubishiG-50a Firmware Version >= 2.50 <= 3.35
   MitsubishiG-50a Version-
MitsubishiGb-50a Firmware Version >= 2.50 <= 3.35
   MitsubishiGb-50a Version-
MitsubishiAg-150a-a Firmware Version <= 3.20
   MitsubishiAg-150a-a Version-
MitsubishiAg-150a-j Firmware Version <= 3.20
   MitsubishiAg-150a-j Version-
MitsubishiGb-50ada-a Firmware Version <= 3.20
   MitsubishiGb-50ada-a Version-
MitsubishiGb-50ada-j Firmware Version <= 3.20
   MitsubishiGb-50ada-j Version-
MitsubishiEb-50gu-a Firmware Version <= 7.09
   MitsubishiEb-50gu-a Version-
MitsubishiEb-50gu-j Firmware Version <= 7.09
   MitsubishiEb-50gu-j Version-
MitsubishiAe-200a Firmware Version <= 7.93
   MitsubishiAe-200a Version-
MitsubishiAe-200e Firmware Version <= 7.93
   MitsubishiAe-200e Version-
MitsubishiAe-50a Firmware Version <= 7.93
   MitsubishiAe-50a Version-
MitsubishiAe-50e Firmware Version <= 7.93
   MitsubishiAe-50e Version-
MitsubishiEw-50a Firmware Version <= 7.93
   MitsubishiEw-50a Version-
MitsubishiEw-50e Firmware Version <= 7.93
   MitsubishiEw-50e Version-
MitsubishiTe-200a Firmware Version <= 7.93
   MitsubishiTe-200a Version-
MitsubishiTe-50a Firmware Version <= 7.93
   MitsubishiTe-50a Version-
MitsubishiTw-50a Firmware Version <= 7.93
   MitsubishiTw-50a Version-
MitsubishiCms-rmd-j Firmware Version <= 1.30
   MitsubishiCms-rmd-j Version-
MitsubishiPac-yg50eca Firmware Version <= 2.20
   MitsubishiPac-yg50eca Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.15% 0.367
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.2 3.9 4.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
nvd@nist.gov 8.5 10 7.8
AV:N/AC:L/Au:N/C:P/I:N/A:C
CWE-611 Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.