ZeroHour

CVE-2021-36200

CVSS 3.1
5.3 medium
EPSS
<1%p49
Published
()
Modified
Description

Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.2 and enumerate users.

Vendors
johnsoncontrols
Products
metasys application and data server, metasys extended application and data server, metasys open application server
Weakness
CWE-306
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.