CVE-2022-21934
Last modified
CVE-2022-21934 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. Under certain circumstances an authenticated user could lock other users out of the system or take over their accounts in Metasys ADS/ADX/OAS server 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS server 11 versions prior to 11.0.2.. EPSS estimates a 0.85% chance of exploitation in the next 30 days.
Description
Under certain circumstances an authenticated user could lock other users out of the system or take over their accounts in Metasys ADS/ADX/OAS server 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS server 11 versions prior to 11.0.2.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Johnsoncontrols | Metasys Application And Data Server | >= 10.0, < 10.1.5 |
| Johnsoncontrols | Metasys Application And Data Server | >= 11.0, < 11.0.2 |
| Johnsoncontrols | Metasys Extended Application And Data Server | >= 10.0, < 10.1.5 |
| Johnsoncontrols | Metasys Extended Application And Data Server | >= 11.0, < 11.0.2 |
| Johnsoncontrols | Metasys Open Application Server | >= 10.0, < 10.1.5 |
| Johnsoncontrols | Metasys Open Application Server | >= 11.0, < 11.0.2 |
References
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-125-01Mitigation, Third Party Advisory, US Government Resource
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-125-01Mitigation, Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-21934?
How severe is CVE-2022-21934?
How do I fix CVE-2022-21934?
Are you affected by CVE-2022-21934?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
