Vulnerabilities > Johnsoncontrols > Exacqvision WEB Service
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2021-10-11 | CVE-2021-27664 | Improper Privilege Management vulnerability in Johnsoncontrols Exacqvision web Service 20.06.11.0/20.06.3.0 Under certain configurations an unauthenticated remote user could be given access to credentials stored in the exacqVision Server. | 6.8 |
2021-06-24 | CVE-2021-27659 | Cross-site Scripting vulnerability in Johnsoncontrols Exacqvision web Service 20.06.3.0/21.03 exacqVision Web Service 21.03 does not sufficiently validate, filter, escape, and/or encode user-controllable input before it is placed in output that is used as a web page that is served to other users. | 4.3 |
2021-03-18 | CVE-2021-27656 | Missing Authorization vulnerability in Johnsoncontrols Exacqvision web Service A vulnerability in exacqVision Web Service 20.12.2.0 and prior could allow an unauthenticated attacker to view system-level information about the exacqVision Web Service and the operating system. | 5.0 |
2020-06-26 | CVE-2020-9047 | Improper Verification of Cryptographic Signature vulnerability in Johnsoncontrols products A vulnerability exists that could allow the execution of unauthorized code or operating system commands on systems running exacqVision Web Service versions 20.06.3.0 and prior and exacqVision Enterprise Manager versions 20.06.4.0 and prior. | 9.0 |