7.5
CVSSv3

CVE-2021-36204

Published: 13/01/2023 Updated: 23/01/2023
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Under some circumstances an Insufficiently Protected Credentials vulnerability in Johnson Controls Metasys ADS/ADX/OAS 10 versions before 10.1.6 and 11 versions before 11.0.3 allows API calls to expose credentials in plain text.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

johnsoncontrols metasys application and data server

johnsoncontrols metasys extended application and data server

johnsoncontrols metasys open application server

ICS Advisories

Johnson Controls Metasys
Critical Infrastructure Sectors: Critical Manufacturing