ZeroHour

CVE-2021-36207

CVSS 3.1
8.8 high
EPSS
<1%p59
Published
()
Modified
Description

Under certain circumstances improper privilege management in Metasys ADS/ADX/OAS servers versions 10 and 11 could allow an authenticated user to elevate their privileges to administrator.

Vendors
johnsoncontrols
Products
metasys application and data server, metasys extended application and data server, metasys open application server
Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.