- What is the severity of CVE-2021-36203?
- CVE-2021-36203 has been scored as a medium severity vulnerability.
- How to fix CVE-2021-36203?
- To fix CVE-2021-36203: Johnson Controls recommends users take the following steps to mitigate this vulnerability: Update SCT/SCT Pro with Patch 14.2.2 Take proper steps to minimize risks to all building automation systems. For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2022-03 v1
- Is CVE-2021-36203 being actively exploited in the wild?
- As for now, there are no information to confirm that CVE-2021-36203 is being actively exploited. According to its EPSS score, there is a ~0% probability that this vulnerability will be exploited by malicious actors in the next 30 days.
- What software or system is affected by CVE-2021-36203?
- CVE-2021-36203 affects Johnnson Controls Metasys System Configuration Tool (SCT), Johnnson Controls Metasys System Configuration Tool Pro (SCT Pro).