Vulnerabilities > Johnsoncontrols > Exacqvision Enterprise Manager > 20.06.4.0

DATE CVE VULNERABILITY TITLE RISK
2021-06-24 CVE-2021-27658 Cross-site Scripting vulnerability in Johnsoncontrols Exacqvision Enterprise Manager 20.06.4.0/20.12
exacqVision Enterprise Manager 20.12 does not sufficiently validate, filter, escape, and/or encode user-controllable input before it is placed in output that is used as a web page that is served to other users.
3.5
2020-06-26 CVE-2020-9047 Improper Verification of Cryptographic Signature vulnerability in Johnsoncontrols products
A vulnerability exists that could allow the execution of unauthorized code or operating system commands on systems running exacqVision Web Service versions 20.06.3.0 and prior and exacqVision Enterprise Manager versions 20.06.4.0 and prior.
network
low complexity
johnsoncontrols CWE-347
critical
9.0