8.8
CVSSv3

CVE-2022-21934

Published: 06/05/2022 Updated: 16/05/2022
CVSS v2 Base Score: 6 | Impact Score: 6.4 | Exploitability Score: 6.8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 535
Vector: AV:N/AC:M/Au:S/C:P/I:P/A:P

Vulnerability Summary

Under certain circumstances an authenticated user could lock other users out of the system or take over their accounts in Metasys ADS/ADX/OAS server 10 versions before 10.1.5 and Metasys ADS/ADX/OAS server 11 versions before 11.0.2.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

johnsoncontrols metasys open application server

johnsoncontrols metasys extended application and data server

johnsoncontrols metasys application and data server

ICS Advisories

Johnson Controls Metasys
Critical Infrastructure Sectors: Critical Manufacturing