CVE-2021-27657
Summary
| CVE | CVE-2021-27657 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-06-04 15:15:00 UTC |
| Updated | 2021-12-02 13:55:00 UTC |
| Description | Successful exploitation of this vulnerability could give an authenticated Metasys user an unintended level of access to the server file system, allowing them to access or modify system files by sending specifically crafted web messages to the Metasys system. This issue affects: Johnson Controls Metasys version 11.0 and prior versions. |
Risk And Classification
Problem Types: CWE-269
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Johnsoncontrols | Metasys | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Product Security Advisories | CONFIRM | www.johnsoncontrols.com | |
| ICS-CERT Advisories | CISA | CERT | us-cert.gov | |
| Johnson Controls Metasys | CISA | CERT | us-cert.cisa.gov | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Jakub Palaczynski
There are currently no legacy QID mappings associated with this CVE.