CVE-2021-36204

CVSS V2 None CVSS V3 None
Description
Under some circumstances an Insufficiently Protected Credentials vulnerability in Johnson Controls Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.3 allows API calls to expose credentials in plain text.
Overview
  • CVE ID
  • CVE-2021-36204
  • Assigner
  • productsecurity@jci.com
  • Vulnerability Status
  • Analyzed
  • Published Version
  • 2023-01-13T21:15:15
  • Last Modified Date
  • 2023-01-23T18:29:40
CPE Configuration (Product)
CPE Vulnerable Operator Version Start Version End
cpe:2.3:a:johnsoncontrols:metasys_application_and_data_server:*:*:*:*:*:*:*:* 1 OR 10.0 10.1.6
cpe:2.3:a:johnsoncontrols:metasys_application_and_data_server:*:*:*:*:*:*:*:* 1 OR 11.0 11.0.3
cpe:2.3:a:johnsoncontrols:metasys_extended_application_and_data_server:*:*:*:*:*:*:*:* 1 OR 10.0 10.1.6
cpe:2.3:a:johnsoncontrols:metasys_extended_application_and_data_server:*:*:*:*:*:*:*:* 1 OR 11.0 11.0.3
cpe:2.3:a:johnsoncontrols:metasys_open_application_server:*:*:*:*:*:*:*:* 1 OR 10.0 10.1.6
cpe:2.3:a:johnsoncontrols:metasys_open_application_server:*:*:*:*:*:*:*:* 1 OR 11.0 11.0.3
History
Created Old Value New Value Data Type Notes
2023-01-13 21:17:40 Added to TrackCVE
2023-01-13 21:17:42 Weakness Enumeration new
2023-01-17 14:14:46 2023-01-17T13:25:00 CVE Modified Date updated
2023-01-17 14:14:46 Received Awaiting Analysis Vulnerability Status updated
2023-01-20 15:14:50 Awaiting Analysis Undergoing Analysis Vulnerability Status updated
2023-01-23 19:14:05 2023-01-23T18:29:40 CVE Modified Date updated
2023-01-23 19:14:05 Undergoing Analysis Analyzed Vulnerability Status updated
2023-01-23 19:14:09 CPE Information updated