CVE-2021-36206 - CVE House
Back to Database
Status published Critical CVE-2021-36206

CEVAS

Vulnerability Description

All versions of CEVAS prior to 1.01.46 do not sufficiently validate user-controllable input and could allow a user to bypass authentication and retrieve data with specially crafted SQL queries.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-36206

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Christian Vierschilling and Caroline Moesler reported this vulnerability to Johnson Controls, Inc.

Affected Vendor

Johnson Controls

View all reports →

Affected Software

CEVAS
Vulnerable Versions:
all versions prior to 1.01.46

Timeline

Official Publish: October 28th, 2022
Last Modified: May 5th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N

Weaknesses (CWE)