CVE-2021-27664: exacqVision Web Service
Under certain configurations an unauthenticated remote user could be given access to credentials stored in the exacqVision Server.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-27664?
CVE-2021-27664 is a vulnerability that allows an unauthenticated remote user to access credentials stored in the exacqVision Server.
How severe is CVE-2021-27664?
CVE-2021-27664 has a severity rating of 9.8, which is considered critical.
What software is affected by CVE-2021-27664?
The Johnsoncontrols Exacqvision Web Service version 20.06.11.0 is affected by CVE-2021-27664.
How can I fix CVE-2021-27664?
To fix CVE-2021-27664, it is recommended to update to a patched version of the Johnsoncontrols Exacqvision Web Service.
Where can I find more information about CVE-2021-27664?
You can find more information about CVE-2021-27664 in the following references: [US-CERT Advisory](https://us-cert.gov/ics/advisories/icsa-21-280-01) and [Johnson Controls Security Advisories](https://www.johnsoncontrols.com/cyber-solutions/security-advisories).