Successful exploitation of this vulnerability could give an authenticated Metasys user an unintended level of access to the server file system, allowing them to access or modify system files by sending specifically crafted web messages to the Metasys system. This issue affects: Johnson Controls Metasys version 11.0 and prior versions.
References
Link | Resource |
---|---|
https://us-cert.cisa.gov/ics/advisories/icsa-21-159-01 | Third Party Advisory US Government Resource |
https://us-cert.gov/ics/advisories | Third Party Advisory US Government Resource |
https://www.johnsoncontrols.com/cyber-solutions/security-advisories | Vendor Advisory |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: jci
Published: 2021-06-04T00:00:00
Updated: 2021-06-23T10:45:14
Reserved: 2021-02-24T00:00:00
Link: CVE-2021-27657
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-06-04T15:15:07.517
Modified: 2021-12-02T13:55:35.607
Link: CVE-2021-27657
JSON object: View
Redhat Information
No data.
CWE