CVE-2022-21934: Metasys Unverified Password Change
Under certain circumstances an authenticated user could lock other users out of the system or take over their accounts in Metasys ADS/ADX/OAS server 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS server 11 versions prior to 11.0.2.
Affected Software
Remediation
Information
Information
Event History
Frequently Asked Questions
What is CVE-2022-21934?
CVE-2022-21934 is a vulnerability in Metasys ADS/ADX/OAS server 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS server 11 versions prior to 11.0.2 that allows an authenticated user to lock other users out of the system or take over their accounts.
How does CVE-2022-21934 affect Johnsoncontrols Metasys Application And Data Server?
Johnsoncontrols Metasys Application And Data Server versions prior to 10.1.5 are affected by CVE-2022-21934.
How does CVE-2022-21934 affect Johnsoncontrols Metasys Extended Application And Data Server?
Johnsoncontrols Metasys Extended Application And Data Server versions prior to 10.1.5 are affected by CVE-2022-21934.
How does CVE-2022-21934 affect Johnsoncontrols Metasys Open Application Server?
Johnsoncontrols Metasys Open Application Server versions prior to 10.1.5 are affected by CVE-2022-21934.
What is the severity of CVE-2022-21934?
CVE-2022-21934 has a severity rating of 8.8 (high).
What is the Common Weakness Enumeration (CWE) ID for CVE-2022-21934?
The CWE ID for CVE-2022-21934 is CWE-287 and CWE-620.
How can I fix CVE-2022-21934?
To fix CVE-2022-21934, upgrade Metasys ADS/ADX/OAS server to version 10.1.5 or 11.0.2 depending on the affected version.
Where can I find more information about CVE-2022-21934?
You can find more information about CVE-2022-21934 on the CISA website and Johnson Controls security advisories.