First published: Mon Oct 11 2021(Updated: )
Under certain configurations an unauthenticated remote user could be given access to credentials stored in the exacqVision Server.
Credit: productsecurity@jci.com
Affected Software | Affected Version | How to fix |
---|---|---|
Johnsoncontrols Exacqvision Web Service | <=20.06.11.0 |
Upgrade exacqVision Web Service to version 21.09. Current users can obtain the critical software update from the Software Download location at: https://www.exacq.com/support/downloads.php
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27664 is a vulnerability that allows an unauthenticated remote user to access credentials stored in the exacqVision Server.
CVE-2021-27664 has a severity rating of 9.8, which is considered critical.
The Johnsoncontrols Exacqvision Web Service version 20.06.11.0 is affected by CVE-2021-27664.
To fix CVE-2021-27664, it is recommended to update to a patched version of the Johnsoncontrols Exacqvision Web Service.
You can find more information about CVE-2021-27664 in the following references: [US-CERT Advisory](https://us-cert.gov/ics/advisories/icsa-21-280-01) and [Johnson Controls Security Advisories](https://www.johnsoncontrols.com/cyber-solutions/security-advisories).