CVE-2021-36204: Insufficiently Protected Credentials in Metasys
Under some circumstances an Insufficiently Protected Credentials vulnerability in Johnson Controls Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.3 allows API calls to expose credentials in plain text.
Affected Software
Remediation
Information
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this Johnson Controls Metasys ADS/ADX/OAS vulnerability?
The vulnerability ID for this Johnson Controls Metasys ADS/ADX/OAS vulnerability is CVE-2021-36204.
What is the severity of CVE-2021-36204?
The severity of CVE-2021-36204 is high with a CVSS score of 7.5.
Which versions of Johnson Controls Metasys ADS/ADX/OAS are affected by this vulnerability?
Johnson Controls Metasys ADS/ADX/OAS versions prior to 10.1.6 and 11 versions prior to 11.0.3 are affected by this vulnerability.
What is the risk of the vulnerability?
The vulnerability exposes credentials in plain text, posing a significant risk to the system and the confidentiality of the exposed credentials.
How can I fix CVE-2021-36204?
To fix the vulnerability, update Johnson Controls Metasys ADS/ADX/OAS to version 10.1.6 or higher for 10.x versions, or version 11.0.3 or higher for 11.x versions.