CVE-2018-10624 - CVE House
Back to Database
Status published Medium CVE-2018-10624

Johnson Controls Metasys and BCPro Generation of Error Message Containing Sensitive Information

Vulnerability Description

In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could allow an attacker to obtain technical information.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-10624

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Dan Regalado of Zingbox reported this vulnerability to CISA.

Affected Vendor

Johnson Controls

View all reports →

Affected Software

Metasys System, BCPro (BCM)
Vulnerable Versions:
0

Timeline

Official Publish: August 1st, 2018
Last Modified: September 17th, 2024
Added to House: July 20th, 2026

CVSS Vectors

V3: CVSS:3.0/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Weaknesses (CWE)