In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the se…
Medium CVSS 4.3
Summary
In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could allow an attacker to obtain technical information.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- http://www.securityfocus.com/bid/104937 Third Party Advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-18-212-02
- http://www.securityfocus.com/bid/104937 Third Party Advisory
- https://ics-cert.us-cert.gov/advisories/ICSA-18-212-02 Mitigation
Timeline
- nvd_ingest NVD