First published: Fri Apr 29 2022(Updated: )
Under certain circumstances improper privilege management in Metasys ADS/ADX/OAS servers versions 10 and 11 could allow an authenticated user to elevate their privileges to administrator.
Credit: productsecurity@jci.com
Affected Software | Affected Version | How to fix |
---|---|---|
Johnsoncontrols Metasys Application And Data Server | >=10.0<10.1.5 | |
Johnsoncontrols Metasys Application And Data Server | >=11.0<11.0.2 | |
Johnsoncontrols Metasys Extended Application And Data Server | >=10.0<10.1.5 | |
Johnsoncontrols Metasys Extended Application And Data Server | >=11.0<11.0.2 | |
Johnsoncontrols Metasys Open Application Server | >=10.0<10.1.5 | |
Johnsoncontrols Metasys Open Application Server | >=11.0<11.0.2 | |
Johnson Controls, Inc. All Metasys ADS/ADX/OAS Servers: Versions 10 and 11 |
Update all Metasys ADS/ADX/OAS Servers versions 10 with patch 10.1.5
Update all Metasys ADS/ADX/OAS Servers versions 11 with patch 11.0.2
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-36207 refers to a vulnerability in Metasys ADS/ADX/OAS servers versions 10 and 11 that allows an authenticated user to elevate their privileges to administrator.
Metasys ADS/ADX/OAS servers versions 10.0 to 10.1.5 and versions 11.0 to 11.0.2 are affected.
CVE-2021-36207 has a severity rating of 8.8, which is considered high.
An authenticated user can exploit CVE-2021-36207 by leveraging improper privilege management to elevate their privileges to administrator.
Yes, you can find more information about CVE-2021-36207 at the following references: [CISA Advisory](https://www.cisa.gov/uscert/ics/advisories/icsa-22-118-01) and [Johnson Controls Security Advisories](https://www.johnsoncontrols.com/cyber-solutions/security-advisories).