nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-27664 CVE-2021-27664
CRITICAL
exacqVision Web Service
Record summary
CVE-2021-27664 has a selected CVSS score of 9.8 (critical).
Description
Under certain configurations an unauthenticated remote user could be given access to credentials stored in the exacqVision Server.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
exacqVision Web ServiceBrowse Johnson Controls / exacqVision Web Service | CVE List | 21.06.11.0 to ≤ 21.06.11.0 | affected |
References
3ICS-CERT AdvisoryThird-party advisory
https://us-cert.gov/ics/advisories/icsa-21-280-01 johnsoncontrols.comConfirmation
https://www.johnsoncontrols.com/cyber-solutions/security-advisories