CVE-2018-10624
בינונית 4.3
תיאור (מקור, אנגלית)
In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could allow an attacker to obtain technical information.
מדדים
- CVSS 3.1
-
4.3 (MEDIUM)
מקור הציון: CNA
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N - EPSS — סבירות ניצול
- 1% (אחוזון 100) נכון ל-16/9/2026
- CWE
- CWE-209, CWE-388
מוצרים מושפעים
johnsoncontrols: bcpro; johnsoncontrols: metasys system
קישורים
- http://www.securityfocus.com/bid/104937 Third Party AdvisoryVDB Entry
- https://www.cisa.gov/news-events/ics-advisories/icsa-18-212-02
- http://www.securityfocus.com/bid/104937 Third Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-18-212-02 MitigationThird Party AdvisoryUS Government Resource