In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could allow an attacker to obtain technical information.
Metrics
Affected Vendors & Products
References
History
Thu, 10 Sep 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
cvssV3_1
|
Tue, 17 Sep 2024 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could allow an attacker to obtain technical information. | In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could allow an attacker to obtain technical information. |
Status: PUBLISHED
Assigner: icscert
Published: 2018-08-01T21:00:00.000Z
Updated: 2026-09-10T17:08:19.667Z
Reserved: 2018-05-01T00:00:00.000Z
Link: CVE-2018-10624
No data.
Status : Modified
Published: 2018-08-01T21:29:00.217
Modified: 2026-09-10T17:17:00.227
Link: CVE-2018-10624
No data.
ReportizFlow