A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems AC2000 allows a remote attacker to access to the system without adequate authorization. This issue affects: Johnson Controls CEM Systems AC2000 10.1; 10.2; 10.3; 10.4; 10.5.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-14409 | A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems AC2000 allows a remote attacker to access to the system without adequate authorization. This issue affects: Johnson Controls CEM Systems AC2000 10.1; 10.2; 10.3; 10.4; 10.5. |
Fixes
Solution
Apply a patch to all affected versions and implementations. The fix will also be included in 10.5 Server Feature Pack 2, version 10.6 and all future releases. To access the patch, affected users should contact their CEM support team: https://www.cemsys.com/support/technical-helpdesk/
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: jci
Published:
Updated: 2024-09-17T03:38:42.161Z
Reserved: 2021-02-24T00:00:00
Link: CVE-2021-27663
No data.
Status : Modified
Published: 2021-08-30T18:15:08.663
Modified: 2024-11-21T05:58:24.147
Link: CVE-2021-27663
No data.
OpenCVE Enrichment
No data.
EUVD