CVE-2022-21936: Metasys MVE
Published Oct 7, 2022
·Updated
On Metasys ADX Server version 12.0 running MVE, an Active Directory user could execute validated actions without providing a valid password when using MVE SMP UI.
Affected Software
3 affected components
Johnson Controls Inc. Metasys ADX Server version 12.0 running MVE
All of the following
Johnsoncontrols Metasys Extended Application And Data Server=12.0
Johnsoncontrols Metasys For Validated Environments
Remediation
Information
Update Metasys ADX Server version 12.0 running MVE with patch 12.0.1.
Event History
Oct 7, 2022
CVE Published
via MITRE·05:39 PM
Data Sourced
via MITRE·05:39 PM
RemedyDescriptionSeverity
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-21936.
2
What version of Metasys ADX Server is affected?
Metasys ADX Server version 12.0 is affected.
3
How can an Active Directory user execute validated actions without a valid password?
An Active Directory user can execute validated actions without a valid password when using MVE SMP UI on Metasys ADX Server version 12.0.
4
What is the severity of CVE-2022-21936?
The severity of CVE-2022-21936 is high with a CVSS score of 6.5.
5
How can I fix the vulnerability CVE-2022-21936?
To fix the vulnerability, update Metasys ADX Server to a version that is not affected or apply the necessary patches provided by the vendor.