Lucene search

K
cvelistJciCVELIST:CVE-2021-27659
HistoryJun 24, 2021 - 1:59 p.m.

CVE-2021-27659 exacqVision Web Service CSS

2021-06-2413:59:12
CWE-79
jci
www.cve.org
2
cve-2021-27659
exacqvision
web service
input validation

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

EPSS

0.001

Percentile

31.6%

exacqVision Web Service 21.03 does not sufficiently validate, filter, escape, and/or encode user-controllable input before it is placed in output that is used as a web page that is served to other users.

CNA Affected

[
  {
    "product": "exacqVision Web Service",
    "vendor": "Johnson Controls",
    "versions": [
      {
        "lessThanOrEqual": "21.03",
        "status": "affected",
        "version": "All versions up to and including 21.03",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

5.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

EPSS

0.001

Percentile

31.6%

Related for CVELIST:CVE-2021-27659