In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could allow an attacker to obtain technical information.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Bcpro | Johnsoncontrols | * | 3.0.2 (excluding) |
Metasys_system | Johnsoncontrols | * | 8.0 (including) |