A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems AC2000 allows a remote attacker to access to the system without adequate authorization. This issue affects: Johnson Controls CEM Systems AC2000 10.1; 10.2; 10.3; 10.4; 10.5.
Advisories
Source ID Title
EUVD EUVD EUVD-2021-14409 A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems AC2000 allows a remote attacker to access to the system without adequate authorization. This issue affects: Johnson Controls CEM Systems AC2000 10.1; 10.2; 10.3; 10.4; 10.5.
Fixes

Solution

Apply a patch to all affected versions and implementations. The fix will also be included in 10.5 Server Feature Pack 2, version 10.6 and all future releases. To access the patch, affected users should contact their CEM support team: https://www.cemsys.com/support/technical-helpdesk/


Workaround

No workaround given by the vendor.

History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: jci

Published:

Updated: 2024-09-17T03:38:42.161Z

Reserved: 2021-02-24T00:00:00

Link: CVE-2021-27663

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-08-30T18:15:08.663

Modified: 2024-11-21T05:58:24.147

Link: CVE-2021-27663

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.