Johnson Controls Metasys and BCPro Generation of Error Message Containing Sensitive Information
Vulnerability Description
In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could allow an attacker to obtain technical information.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2018-10624
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Dan Regalado of Zingbox reported this vulnerability to CISA.
References
More from Johnson Controls
View All →Affected Vendor
Johnson Controls
View all reports →