Vulnerabilities (CVE)

Filtered by vendor Johnsoncontrols Subscribe
Filtered by product Metasys For Validated Environments
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2022-21936 1 Johnsoncontrols 2 Metasys Extended Application And Data Server, Metasys For Validated Environments 2024-11-21 N/A 8.1 HIGH
On Metasys ADX Server version 12.0 running MVE, an Active Directory user could execute validated actions without providing a valid password when using MVE SMP UI.