CVE-2021-36205: Metasys session token
Under certain circumstances the session token is not cleared on logout.
Affected Software
Remediation
Information
Information
Event History
Frequently Asked Questions
What is CVE-2021-36205?
CVE-2021-36205 refers to a vulnerability where under certain circumstances the session token is not cleared on logout.
What software is affected by CVE-2021-36205?
Johnsoncontrols Metasys Application And Data Server versions 10.0 to 10.1.5, Johnsoncontrols Metasys Application And Data Server versions 11.0 to 11.0.2, Johnsoncontrols Metasys Extended Application And Data Server versions 10.0 to 10.1.5, Johnsoncontrols Metasys Extended Application And Data Server versions 11.0 to 11.0.2, Johnsoncontrols Metasys Open Application Server versions 10.0 to 10.1.5, and Johnsoncontrols Metasys Open Application Server versions 11.0 to 11.0.2 are affected.
What is the severity of CVE-2021-36205?
CVE-2021-36205 has a severity rating of 9.8 (critical).
How can I fix CVE-2021-36205?
To fix CVE-2021-36205, apply the necessary updates or patches provided by Johnsoncontrols.
Where can I find more information about CVE-2021-36205?
You can find more information about CVE-2021-36205 on the CISA website and the Johnsoncontrols security advisories page.