CVE-2018-10624: Johnson Controls Metasys and BCPro Generation of Error Message Containing Sensitive Information
In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could allow an attacker to obtain technical information.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this Johnson Controls Metasys System vulnerability?
The vulnerability ID for this Johnson Controls Metasys System vulnerability is CVE-2018-10624.
What is the severity of CVE-2018-10624?
The severity of CVE-2018-10624 is medium with a CVSS score of 6.5.
What is the affected software for CVE-2018-10624?
The affected software for CVE-2018-10624 includes Johnson Controls BCPro versions prior to 3.0.2 and Johnson Controls Metasys System versions prior to 8.0.
What is the description of CVE-2018-10624?
CVE-2018-10624 is a vulnerability in Johnson Controls Metasys System and BCPro, allowing an attacker to obtain technical information by exploiting improper error handling in HTTP-based communications with the server.
Are there any references available for CVE-2018-10624?
Yes, there are references available for CVE-2018-10624. You can find more information at the following links: http://www.securityfocus.com/bid/104937 and https://ics-cert.us-cert.gov/advisories/ICSA-18-212-02.