Impact
The vulnerability is an improper neutralization of user input during web page generation, which allows an attacker to inject malicious scripts that execute in the context of the victim’s browser. This cross‑site scripting flaw enables client‑side code execution, potentially leaking session data, defacing pages, or facilitating phishing attacks. The weakness is classified as CWE‑79.
Affected Systems
Johnson Controls Metasys 14 versions prior to 14.1.5 and Johnson Controls Metasys 15 versions prior to 15.0.1 are affected. These are industrial building automation platforms that provide web‑based management interfaces.
Risk and Exploitability
The CVSS score is 6.1, indicating a high severity. EPSS data is not available, so the likelihood of real‑world exploitation is currently unknown, but cross‑site scripting is a well‑known attack vector. The vulnerability is not listed in CISA’s KEV catalogue, and no public exploit has been reported. Based on the description, it is inferred that the attack vector involves web requests to the Metasys web interface, where crafted input can be supplied and reflected back to users.
OpenCVE Enrichment