cve/2021/CVE-2021-36204.md

19 lines
916 B
Markdown
Raw Normal View History

2025-09-29 21:09:30 +02:00
### [CVE-2021-36204](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-36204)
![](https://img.shields.io/static/v1?label=Product&message=Metasys%20ADS%2FADX%2FOAS&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=All%2010%20versions%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Version&message=All%2011%20versions%20&color=brightgreen)
![](https://img.shields.io/static/v1?label=Vulnerability&message=CWE-522%3A%20Insufficiently%20Protected%20Credentials&color=brightgreen)
### Description
Under some circumstances an Insufficiently Protected Credentials vulnerability in Johnson Controls Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.3 allows API calls to expose credentials in plain text.
### POC
#### Reference
- https://www.johnsoncontrols.com/cyber-solutions/security-advisories
#### Github
No PoCs found on GitHub currently.