CVE-2021-27657: Metasys Improper Privilege Management
Successful exploitation of this vulnerability could give an authenticated Metasys user an unintended level of access to the server file system, allowing them to access or modify system files by sending specifically crafted web messages to the Metasys system. This issue affects: Johnson Controls Metasys version 11.0 and prior versions.
Affected Software
Remediation
Information
Information
Event History
Frequently Asked Questions
What is CVE-2021-27657?
CVE-2021-27657 is a vulnerability that allows authenticated Metasys users to gain unintended access to the server file system and modify system files.
How does CVE-2021-27657 impact Johnson Controls Metasys?
CVE-2021-27657 affects Johnson Controls Metasys version up to and including 11.0, allowing authenticated users to manipulate system files.
What is the severity of CVE-2021-27657?
CVE-2021-27657 has a severity rating of high with a score of 8.8.
How can an attacker exploit CVE-2021-27657?
An attacker can exploit CVE-2021-27657 by sending specifically crafted web messages to the Metasys system, gaining unauthorized access to sensitive files.
Is there a fix for CVE-2021-27657?
Yes, it is recommended to update Johnson Controls Metasys to a version beyond 11.0 to mitigate the vulnerability.