First published: Thu Jul 01 2021(Updated: )
Successful exploitation of this vulnerability could give an authenticated Facility Explorer SNC Series Supervisory Controller (F4-SNC) user an unintended level of access to the controller’s file system, allowing them to access or modify system files by sending specifically crafted web messages to the F4-SNC.
Credit: productsecurity@jci.com
Affected Software | Affected Version | How to fix |
---|---|---|
Johnsoncontrols F4-snc Firmware | =11 | |
Johnsoncontrols F4-snc | ||
Johnson Controls Facility Explorer SNC Series Supervisory Controller | =11 |
Apply a patch to the Facility Explorer SNC Series Supervisory Controllers (F4-SNC).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27661 is a vulnerability that allows an authenticated user of the Facility Explorer SNC Series Supervisory Controller (F4-SNC) to gain unauthorized access to the controller's file system.
CVE-2021-27661 affects Johnson Controls F4-SNC firmware version 11, allowing an authenticated user to access or modify system files.
CVE-2021-27661 has a severity rating of 8.8, which is classified as high severity.
To fix CVE-2021-27661, users should apply the necessary patches or updates provided by Johnson Controls.
More information about CVE-2021-27661 can be found on the official websites of US-CERT and Johnson Controls.