Critical Infrastructure Sectors: Critical Manufacturing
Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions before 10.1.6 and 11 versions before 11.0.2 and enumerate users.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
johnsoncontrols metasys open application server |
||
johnsoncontrols metasys extended application and data server |
||
johnsoncontrols metasys application and data server |