ZeroHour

CVE-2018-10624

CVSS 3.1
4.3 medium
EPSS
<1%p54
Published
()
Modified
Description

In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could allow an attacker to obtain technical information.

Vendors
johnsoncontrols
Products
bcpro, metasys system
Weakness
CWE-209, CWE-388
Vector
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.