5.3
CVSSv3

CVE-2021-36200

Published: 22/07/2022 Updated: 29/07/2022
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions before 10.1.6 and 11 versions before 11.0.2 and enumerate users.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

johnsoncontrols metasys open application server

johnsoncontrols metasys extended application and data server

johnsoncontrols metasys application and data server

ICS Advisories