CVE-2018-10624
4.3
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Summary
In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could allow an attacker to obtain technical information.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Johnson Controls | Metasys System | 0 <= 8.0 | affected |
| Johnson Controls | Metasys System | 9.0 | unaffected |
| Johnson Controls | BCPro (BCM) | 0 < 3.0.2 | affected |
| Johnson Controls | BCPro (BCM) | 3.0.2 | unaffected |
Weaknesses
- CWE-209: CWE-209 Generation of Error Message Containing Sensitive Information
Workarounds
Additional information for Johnson Controls:
- Product security contact information, Building Automation System hardening, and security resources are located at the Johnson Controls product security website http://www.johnsoncontrols.com/buildings/specialty-pages/product-security
- Contact information: Johnson Controls Global Product Security at productsecurity@jci.com http://mailto:productsecurity@jci.com/
ADP Enrichment
CVE Program Container
Additional References
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-18-212-02
- http://www.securityfocus.com/bid/104937
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.