← Back to home
ICSA-21-182-04  ·  Published 2021-07-01  ·  View on CISA ICS-CERT ↗

Mitsubishi Electric Air Conditioning System

CVSS 7.1 HIGH

Risk Summary

An attacker could exploit this vulnerability by impersonating administrators to disclose configuration information of the air conditioning system in order to tamper with operation information and system configuration.

CVEs (1)

Remediations

  • G-50A: Version 3.37 or later
  • GB-50A: Version 3.37 or later
  • AG-150A-A: Version 3.21 or later
  • AG-150A-J: Version 3.21 or later
  • GB-50ADA-A: Version 3.21 or later
  • GB-50ADA-J: Version 3.21 or later
  • EB-50GU-A: Version 7.10 or later
  • EB-50GU-J: Version 7.10 or later
  • AE-200A: Version 7.95 or later
  • AE-200E: Version 7.95 or later
  • AE-50A: Version 7.95 or later
  • AE-50E: Version 7.95 or later
  • EW-50A: Version 7.95 or later
  • EW-50E: Version 7.95 or later
  • TE-200A: Version 7.95 or later
  • TE-50A: Version 7.95 or later
  • TW-50A: Version 7.95 or later
  • CMS-RMD-J: Version 1.40 or later
  • PAC-YG50ECA: Version 2.21 or later
  • Use a VPN router, etc. when connecting the air conditioning system to the Internet.
  • Use an antivirus software computer on systems used to connect conditioning systems.
  • Restrict the access to air conditioning systems from untrusted networks and hosts.
  • Change default usernames and passwords.
  • Please contact a distributor or Mitsubishi Electric representative for available updates.

Affected Vendors

Mitsubishi Electric

Affected Products (19)

Mitsubishi Electric · EB-50GU-J <= 7.09
Mitsubishi Electric · AG-150A-J <= 3.20
Mitsubishi Electric · AG-150A-A <= 3.20
Mitsubishi Electric · CMS-RMD-J <= 1.30
Mitsubishi Electric · EW-50A <= 7.93
Mitsubishi Electric · G-50A >= 2.50 | <= 3.35
Mitsubishi Electric · TW-50A <= 7.93
Mitsubishi Electric · AE-50A <= 7.93
Mitsubishi Electric · GB-50ADA-A <= 3.20
Mitsubishi Electric · EW-50E <= 7.93
Mitsubishi Electric · TE-200A <= 7.93
Mitsubishi Electric · TE-50A <= 7.93
Mitsubishi Electric · GB-50ADA-J <= 3.20
Mitsubishi Electric · AE-50E <= 7.93
Mitsubishi Electric · AE-200A <= 7.93
Mitsubishi Electric · PAC-YG50ECA <= 2.20
Mitsubishi Electric · EB-50GU-A <= 7.09
Mitsubishi Electric · GB-50A >= 2.50 | <= 3.35
Mitsubishi Electric · AE-200E <= 7.93

Affected Sectors

Commercial Facilities

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more