Under certain circumstances improper privilege management in Metasys ADS/ADX/OAS servers versions 10 and 11 could allow an authenticated user to elevate their privileges to administrator.
Solution:
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
Link | Tags |
---|---|
https://www.johnsoncontrols.com/cyber-solutions/security-advisories | vendor advisory |
https://www.cisa.gov/uscert/ics/advisories/icsa-22-118-01 | third party advisory us government resource |