First published: Tue Oct 04 2022(Updated: )
On Metasys ADX Server version 12.0 running MVE, an Active Directory user could execute validated actions without providing a valid password when using MVE SMP UI.
Credit: productsecurity@jci.com
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Johnsoncontrols Metasys Extended Application And Data Server | =12.0 | |
Johnsoncontrols Metasys For Validated Environments | ||
Johnson Controls Inc. Metasys ADX Server version 12.0 running MVE |
Update Metasys ADX Server version 12.0 running MVE with patch 12.0.1.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-21936.
Metasys ADX Server version 12.0 is affected.
An Active Directory user can execute validated actions without a valid password when using MVE SMP UI on Metasys ADX Server version 12.0.
The severity of CVE-2022-21936 is high with a CVSS score of 6.5.
To fix the vulnerability, update Metasys ADX Server to a version that is not affected or apply the necessary patches provided by the vendor.