Vulnerabilities > Johnsoncontrols > Metasys

DATE CVE VULNERABILITY TITLE RISK
2021-06-04 CVE-2021-27657 Improper Privilege Management vulnerability in Johnsoncontrols Metasys 11.0
Successful exploitation of this vulnerability could give an authenticated Metasys user an unintended level of access to the server file system, allowing them to access or modify system files by sending specifically crafted web messages to the Metasys system.
network
low complexity
johnsoncontrols CWE-269
8.8