Johnson Controls Metasys and BCPro Generation of Error Message Containing Sensitive Information
Summary
| CVE | CVE-2018-10624 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-08-01 21:29:00 UTC |
| Updated | 2026-09-10 17:17:00 UTC |
| Description | In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could allow an attacker to obtain technical information. |
Risk And Classification
Primary CVSS: v3.1 4.3 MEDIUM from [email protected]
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS: 0.008770000 probability, percentile 0.569920000 (date 2026-09-13)
Problem Types: CWE-209 | CWE-388 | CWE-209 CWE-209 Generation of Error Message Containing Sensitive Information
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Secondary | 4.3 | MEDIUM | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
| 3.1 | CNA | CVSS | 4.3 | MEDIUM | CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
| 3.0 | [email protected] | Primary | 6.5 | MEDIUM | CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 2.0 | [email protected] | Primary | 3.3 | AV:A/AC:L/Au:N/C:P/I:N/A:N |
CVSS v3.1 Breakdown
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
CVSS v3.0 Breakdown
CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS v2.0 Breakdown
AV:A/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Johnsoncontrols | Bcpro | All | All | All | All |
| Application | Johnsoncontrols | Metasys System | All | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Johnson Controls | Metasys System | affected 8.0 custom | Not specified |
| CNA | Johnson Controls | Metasys System | unaffected 9.0 | Not specified |
| CNA | Johnson Controls | BCPro BCM | affected 3.0.2 custom | Not specified |
| CNA | Johnson Controls | BCPro BCM | unaffected 3.0.2 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Johnson Controls Metasys and BCPro | ICS-CERT | af854a3a-2127-422b-91ae-364da2661108 | ics-cert.us-cert.gov | Mitigation, Third Party Advisory, US Government Resource |
| www.cisa.gov/news-events/ics-advisories/icsa-18-212-02 | [email protected] | www.cisa.gov | |
| Johnson Controls Metasys and BCPro CVE-2018-10624 Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | Third Party Advisory, VDB Entry |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Dan Regalado of Zingbox reported this vulnerability to CISA. (en)
Additional Advisory Data
Solutions
CNA: Johnson Controls recommends the following mitigations: * This issue was remediated in Metasys v8.1 (April, 2016). Users should upgrade to the latest product version (9.0). For Metasys information, contact your Metasys field service/sales representative. * This issue was remediated in the BCPro Workstation in BCPro v3.0 (October, 2017) and mitigated for the BACnet Router and Gateway in BCPro v3.0.2 (June, 2018). Users should upgrade to the latest product versions. For more BCPro information, contact your BCPro sales and support representative.
Workarounds
CNA: Additional information for Johnson Controls: * Product security contact information, Building Automation System hardening, and security resources are located at the Johnson Controls product security website http://www.johnsoncontrols.com/buildings/specialty-pages/product-security * Contact information: Johnson Controls Global Product Security at [email protected] http://mailto:[email protected]/