CVE-2021-36201: CCURE Observable Response Discrepancy
Published Oct 11, 2022
·Updated
Under certain circumstances a CCURE Portal user could enumerate user accounts in CCURE 9000 version 2.90 and prior versions.
Affected Software
3 affected components
Sensormatic Electronics, LLC, a subsidiary of Johnson Controls Inc. C-CURE 9000 version 2.90 and prior
Johnsoncontrols C-cure 9000 Firmware<=2.90
Johnsoncontrols C-cure 9000
Remediation
Information
Update C•CURE 9000 2.90 with patch 2.90 SP5 or upgrade C•CURE 9000 to version 3.0. The software can be downloaded here: https://www.swhouse.com/Support/SoftwareDownloads.aspx
Event History
Oct 11, 2022
CVE Published
via MITRE·08:17 PM
Data Sourced
via MITRE·08:17 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2021-36201.
2
What is the severity of CVE-2021-36201?
The severity of CVE-2021-36201 is medium with a severity value of 5.3.
3
What software versions are affected by CVE-2021-36201?
CCURE 9000 version 2.90 and prior versions are affected by CVE-2021-36201.
4
How can a CCURE Portal user enumerate user accounts in CCURE 9000?
Under certain circumstances, a CCURE Portal user can enumerate user accounts in CCURE 9000 version 2.90 and prior versions.
5
Where can I find more information about CVE-2021-36201?
You can find more information about CVE-2021-36201 at the following references: [CISA Advisory](https://www.cisa.gov/uscert/ics/advisories/icsa-22-284-03) and [Johnson Controls Security Advisories](https://www.johnsoncontrols.com/cyber-solutions/security-advisories).