CVE-2021-36200: Metasys ADS/ADX/OAS with MUI
Published Jul 22, 2022
·Updated
Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.2 and enumerate users.
Affected Software
8 affected components
Johnson Controls Metasys=10
Johnson Controls Metasys=11
Johnsoncontrols Metasys Application And Data Server>=10.0<10.1.6
Johnsoncontrols Metasys Application And Data Server>=11.0<11.0.2
Johnsoncontrols Metasys Extended Application And Data Server>=10.0<10.1.6
Johnsoncontrols Metasys Extended Application And Data Server>=11.0<11.0.2
Johnsoncontrols Metasys Open Application Server>=10.0<10.1.6
Johnsoncontrols Metasys Open Application Server>=11.0<11.0.2
Remediation
Information
Update all Metasys ADS/ADX/OAS 10 versions with patch 10.1.6
Information
Update all Metasys ADS/ADX/OAS 11 versions with patch 11.0.2
Event History
Jul 22, 2022
CVE Published
via MITRE·02:55 PM
Data Sourced
via MITRE·02:55 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-36200.
2
What is the severity of CVE-2021-36200?
The severity of CVE-2021-36200 is medium with a severity value of 5.3.
3
Which software versions are affected by CVE-2021-36200?
Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.2 are affected by CVE-2021-36200.
4
How can an unauthenticated user access the web API for Metasys ADS/ADX/OAS?
Under certain circumstances, an unauthenticated user can access the web API for Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.2.
5
What can an unauthenticated user do if they access the web API for Metasys ADS/ADX/OAS?
If an unauthenticated user accesses the web API for Metasys ADS/ADX/OAS, they can enumerate users.