← Back to home
ICSA-21-182-05  ·  Published 2021-07-01  ·  View on CISA ICS-CERT ↗

Mitsubishi Electric Air Conditioning Systems

CVSS 9.3 CRITICAL

Risk Summary

Successful exploitation of this vulnerability may allow an attacker to disclose some of the data in the air conditioning system or cause a denial-of-service condition.

CVEs (1)

Remediations

  • G-50A: Version 3.37 or later
  • GB-50A: Version 3.37 or later
  • GB-24A: Version 9.12 or later
  • AG-150A-A: Version 3.21 or later
  • AG-150A-J: Version 3.21 or later
  • GB-50ADA-A: Version 3.21 or later
  • GB-50ADA-J: Version 3.21 or later
  • EB-50GU-A: Version 7.10 or later
  • EB-50GU-J: Version 7.10 or later
  • AE-200A: Version 7.95 or later
  • AE-200E: Version 7.95 or later
  • AE-50A: Version 7.95 or later
  • AE-50E: Version 7.95 or later
  • EW-50A: Version 7.95 or later
  • EW-50E: Version 7.95 or later
  • TE-200A: Version 7.95 or later
  • TE-50A: Version 7.95 or later
  • TW-50A: Version 7.95 or later
  • CMS-RMD-J: Version 1.40 or later
  • PAC-YG50ECA: Version 2.21 or later
  • BAC-HD150: Version 2.22 or later
  • Use a VPN router, etc. when you connect air conditioning systems to the Internet.
  • Use anti-virus software on computers connected to air conditioning systems.
  • Restrict the access to air conditioning systems from untrusted networks and hosts.
  • Please refer to the Mitsubishi Electric website for additional details about this issue.

Affected Vendors

Mitsubishi Electric

Affected Products (21)

Mitsubishi Electric · GB-50ADA-J <= 3.20
Mitsubishi Electric · EB-50GU-A <= 7.09
Mitsubishi Electric · EW-50A <= 7.93
Mitsubishi Electric · AG-150A-A <= 3.20
Mitsubishi Electric · TW-50A <= 7.93
Mitsubishi Electric · AE-200A <= 7.93
Mitsubishi Electric · BAC-HD150 <= 2.21
Mitsubishi Electric · GB-50A <= 3.35
Mitsubishi Electric · EB-50GU-J <= 7.09
Mitsubishi Electric · EW-50E <= 7.93
Mitsubishi Electric · AE-50E <= 7.93
Mitsubishi Electric · TE-50A <= 7.93
Mitsubishi Electric · AG-150A-J <= 3.20
Mitsubishi Electric · TE-200A <= 7.93
Mitsubishi Electric · G-50A <= 3.35
Mitsubishi Electric · CMS-RMD-J <= 1.30
Mitsubishi Electric · GB-50ADA-A <= 3.20
Mitsubishi Electric · PAC-YG50ECA <= 2.20
Mitsubishi Electric · AE-200E <= 7.93
Mitsubishi Electric · AE-50A <= 7.93
Mitsubishi Electric · GB-24A <= 9.11

Affected Sectors

Commercial Facilities

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more