8.8
CVSSv3

CVE-2021-36202

Published: 07/04/2022 Updated: 14/04/2022
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Server-Side Request Forgery (SSRF) vulnerability in Johnson Controls Metasys could allow an authenticated malicious user to inject malicious code into the MUI PDF export feature. This issue affects: Johnson Controls Metasys All 10 versions versions before 10.1.5; All 11 versions versions before 11.0.2.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

johnsoncontrols metasys application and data server

johnsoncontrols metasys extended application and data server

johnsoncontrols metasys open application server

ICS Advisories

Johnson Controls Metasys
Critical Infrastructure Sectors: Critical Manufacturing