CVE Vulnerabilities

CVE-2021-36207

Improper Privilege Management

Published: Apr 29, 2022 | Modified: Nov 21, 2024
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
8.5 HIGH
AV:N/AC:M/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

Under certain circumstances improper privilege management in Metasys ADS/ADX/OAS servers versions 10 and 11 could allow an authenticated user to elevate their privileges to administrator.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

NameVendorStart VersionEnd Version
Metasys_application_and_data_serverJohnsoncontrols10.0 (including)10.1.5 (excluding)
Metasys_application_and_data_serverJohnsoncontrols11.0 (including)11.0.2 (excluding)
Metasys_extended_application_and_data_serverJohnsoncontrols10.0 (including)10.1.5 (excluding)
Metasys_extended_application_and_data_serverJohnsoncontrols11.0 (including)11.0.2 (excluding)
Metasys_open_application_serverJohnsoncontrols10.0 (including)10.1.5 (excluding)
Metasys_open_application_serverJohnsoncontrols11.0 (including)11.0.2 (excluding)

Potential Mitigations

References