Vulnerabilities (CVE)

Join the Common Vulnerabilities and Exposures (CVE) community and start to get notified about new vulnerabilities.

Filtered by vendor Johnsoncontrols Subscribe
Filtered by product Metasys For Validated Environments
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-21936 1 Johnsoncontrols 2 Metasys Extended Application And Data Server, Metasys For Validated Environments 2022-10-13 N/A 6.5 MEDIUM
On Metasys ADX Server version 12.0 running MVE, an Active Directory user could execute validated actions without providing a valid password when using MVE SMP UI.