Lucene search

K
cveJciCVE-2021-27661
HistoryJul 01, 2021 - 2:15 p.m.

CVE-2021-27661

2021-07-0114:15:07
CWE-269
CWE-863
jci
web.nvd.nist.gov
39
2
cve-2021-27661
facility explorer
snc series
supervisory controller
file system
unauthorized access

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.4

Confidence

High

EPSS

0.001

Percentile

42.8%

Successful exploitation of this vulnerability could give an authenticated Facility Explorer SNC Series Supervisory Controller (F4-SNC) user an unintended level of access to the controller’s file system, allowing them to access or modify system files by sending specifically crafted web messages to the F4-SNC.

Affected configurations

Nvd
Node
johnsoncontrolsf4-snc_firmwareMatch11
AND
johnsoncontrolsf4-sncMatch-
VendorProductVersionCPE
johnsoncontrolsf4-snc_firmware11cpe:2.3:o:johnsoncontrols:f4-snc_firmware:11:*:*:*:*:*:*:*
johnsoncontrolsf4-snc-cpe:2.3:h:johnsoncontrols:f4-snc:-:*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Facility Explorer SNC Series Supervisory Controllers (F4-SNC)",
    "vendor": "Johnson Controls",
    "versions": [
      {
        "status": "affected",
        "version": "Facility Explorer SNC Series Supervisory Controllers version 11 11"
      }
    ]
  }
]

Social References

More

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.4

Confidence

High

EPSS

0.001

Percentile

42.8%

Related for CVE-2021-27661