Vulnerabilities > Johnsoncontrols > C Cure 9000 Firmware > 2.80

DATE CVE VULNERABILITY TITLE RISK
2022-10-11 CVE-2021-36201 Information Exposure Through Discrepancy vulnerability in Johnsoncontrols C-Cure 9000 Firmware 2.70/2.80/2.90
Under certain circumstances a CCURE Portal user could enumerate user accounts in CCURE 9000 version 2.90 and prior versions.
network
low complexity
johnsoncontrols CWE-203
5.3