On Metasys ADX Server version 12.0 running MVE, an Active Directory user could execute validated actions without providing a valid password when using MVE SMP UI.
References
Link | Resource |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-22-277-01 | Third Party Advisory US Government Resource |
https://www.johnsoncontrols.com/cyber-solutions/security-advisories | Vendor Advisory |
Configurations
Information
Published : 2022-10-07 11:15
Updated : 2022-10-13 06:09
NVD link : CVE-2022-21936
Mitre link : CVE-2022-21936
JSON object : View
CWE
CWE-287
Improper Authentication
Products Affected
johnsoncontrols
- metasys_for_validated_environments
- metasys_extended_application_and_data_server