CVE-2021-27657
Successful exploitation of this vulnerability could give an authenticated Metasys user an unintended level of access to the server file system, allowing them to access or modify system files by sending specifically crafted web messages to the Metasys…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.24%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Successful exploitation of this vulnerability could give an authenticated Metasys user an unintended level of access to the server file system, allowing them to access or modify system files by sending specifically crafted web messages to the Metasys system. This issue affects: Johnson Controls Metasys version 11.0 and prior versions.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.24% probability · 68th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-269
- Affected
- johnsoncontrols/metasys
- Source
- productsecurity@jci.com
References
- https://us-cert.cisa.gov/ics/advisories/icsa-21-159-01Third Party Advisory, US Government Resource
- https://us-cert.gov/ics/advisoriesThird Party Advisory, US Government Resource
- https://www.johnsoncontrols.com/cyber-solutions/security-advisoriesVendor Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-21-159-01Third Party Advisory, US Government Resource
- https://us-cert.gov/ics/advisoriesThird Party Advisory, US Government Resource
- https://www.johnsoncontrols.com/cyber-solutions/security-advisoriesVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.