9.1
CVSSv3

CVE-2021-36203

Published: 22/04/2022 Updated: 03/05/2022
CVSS v2 Base Score: 6.4 | Impact Score: 4.9 | Exploitability Score: 10
CVSS v3 Base Score: 9.1 | Impact Score: 5.2 | Exploitability Score: 3.9
VMScore: 570
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:N

Vulnerability Summary

The affected product may allow an malicious user to identify and forge requests to internal systems by way of a specially crafted request.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

johnsoncontrols metasys system configuration tool

Vendor Advisories

A vulnerability in all versions of SCT/SCT Pro prior to version 1422 allows a remote unauthenticated attacker to identify and forge requests to internal systems via a specially crafted request allowing the attacker to determine if specific files or paths exist This issue affects all versions of SCT/SCT Pro prior to version 1422 ...

ICS Advisories