Under some circumstances an Insufficiently Protected Credentials vulnerability in Johnson Controls Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.3 allows API calls to expose credentials in plain text.

Project Subscriptions

Vendors Products
Johnsoncontrols Subscribe
Metasys Application And Data Server Subscribe
Metasys Extended Application And Data Server Subscribe
Metasys Open Application Server Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2021-22825 Under some circumstances an Insufficiently Protected Credentials vulnerability in Johnson Controls Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.3 allows API calls to expose credentials in plain text.
Fixes

Solution

Update all Metasys ADS/ADX/OAS 10 versions with patch 10.1.6.


Workaround

No workaround given by the vendor.

History

Mon, 07 Apr 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: jci

Published:

Updated: 2025-04-07T19:45:35.972Z

Reserved: 2021-07-06T00:00:00.000Z

Link: CVE-2021-36204

cve-icon Vulnrichment

Updated: 2024-08-04T00:54:51.234Z

cve-icon NVD

Status : Modified

Published: 2023-01-13T21:15:15.360

Modified: 2024-11-21T06:13:18.790

Link: CVE-2021-36204

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses