CVE-2021-27661: Facility Explorer
Successful exploitation of this vulnerability could give an authenticated Facility Explorer SNC Series Supervisory Controller (F4-SNC) user an unintended level of access to the controller’s file system, allowing them to access or modify system files by sending specifically crafted web messages to the F4-SNC.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-27661?
CVE-2021-27661 is a vulnerability that allows an authenticated user of the Facility Explorer SNC Series Supervisory Controller (F4-SNC) to gain unauthorized access to the controller's file system.
How does CVE-2021-27661 impact Johnson Controls F4-SNC firmware version 11?
CVE-2021-27661 affects Johnson Controls F4-SNC firmware version 11, allowing an authenticated user to access or modify system files.
How severe is CVE-2021-27661?
CVE-2021-27661 has a severity rating of 8.8, which is classified as high severity.
How can I fix CVE-2021-27661?
To fix CVE-2021-27661, users should apply the necessary patches or updates provided by Johnson Controls.
Where can I find more information about CVE-2021-27661?
More information about CVE-2021-27661 can be found on the official websites of US-CERT and Johnson Controls.