CVE Vulnerabilities

CVE-2021-36207

Improper Privilege Management

Published: Apr 29, 2022 | Modified: May 11, 2022
CVSS 3.x
8.8
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
8.5 HIGH
AV:N/AC:M/Au:S/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Under certain circumstances improper privilege management in Metasys ADS/ADX/OAS servers versions 10 and 11 could allow an authenticated user to elevate their privileges to administrator.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Affected Software

Name Vendor Start Version End Version
Metasys_application_and_data_server Johnsoncontrols 10.0 (including) 10.1.5 (excluding)
Metasys_application_and_data_server Johnsoncontrols 11.0 (including) 11.0.2 (excluding)
Metasys_extended_application_and_data_server Johnsoncontrols 10.0 (including) 10.1.5 (excluding)
Metasys_extended_application_and_data_server Johnsoncontrols 11.0 (including) 11.0.2 (excluding)
Metasys_open_application_server Johnsoncontrols 10.0 (including) 10.1.5 (excluding)
Metasys_open_application_server Johnsoncontrols 11.0 (including) 11.0.2 (excluding)

Potential Mitigations

References