PT-2021-17591 · Johnson Controls · Ac2000

Published

2021-08-30

·

Updated

2022-10-25

·

CVE-2021-27663

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Johnson Controls CEM Systems AC2000 versions 10.1 through 10.5
Description A remote attacker can access the system without adequate authorization due to a vulnerability.
Recommendations For versions 10.1 through 10.5, update to a version that contains a fix for this issue.

Fix

Improper Authorization

Weakness Enumeration

Related Identifiers

CVE-2021-27663

Affected Products

Ac2000