CVE-2021-36207: Metasys privilege management
Under certain circumstances improper privilege management in Metasys ADS/ADX/OAS servers versions 10 and 11 could allow an authenticated user to elevate their privileges to administrator.
Affected Software
Remediation
Information
Information
Event History
Frequently Asked Questions
What is CVE-2021-36207?
CVE-2021-36207 refers to a vulnerability in Metasys ADS/ADX/OAS servers versions 10 and 11 that allows an authenticated user to elevate their privileges to administrator.
Which software versions are affected by CVE-2021-36207?
Metasys ADS/ADX/OAS servers versions 10.0 to 10.1.5 and versions 11.0 to 11.0.2 are affected.
What is the severity rating of CVE-2021-36207?
CVE-2021-36207 has a severity rating of 8.8, which is considered high.
How can an authenticated user exploit CVE-2021-36207?
An authenticated user can exploit CVE-2021-36207 by leveraging improper privilege management to elevate their privileges to administrator.
Are there any references or resources about CVE-2021-36207?
Yes, you can find more information about CVE-2021-36207 at the following references: [CISA Advisory](https://www.cisa.gov/uscert/ics/advisories/icsa-22-118-01) and [Johnson Controls Security Advisories](https://www.johnsoncontrols.com/cyber-solutions/security-advisories).