CEVAS
Vulnerability Description
All versions of CEVAS prior to 1.01.46 do not sufficiently validate user-controllable input and could allow a user to bypass authentication and retrieve data with specially crafted SQL queries.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-36206
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Christian Vierschilling and Caroline Moesler reported this vulnerability to Johnson Controls, Inc.
References
More from Johnson Controls
View All →Affected Vendor
Johnson Controls
View all reports →