← Back to browse · API

CVE-2021-36206

Severity
CRITICAL
CVSS
10.0
EPSS
0.00433
Risk score
40.15
CISA KEV
No
PoC
No
Published
2022-10-28
Modified
2025-05-05
First seen
2026-08-07
Aliases
EUVD-2021-22827, GHSA-X6W6-PX77-G4XH
Products
Johnson Controls:CEVAS all versions prior to 1.01.46 <1.01.46
Sources
euvd EUVD-2021-22827

Description

All versions of CEVAS prior to 1.01.46 do not sufficiently validate user-controllable input and could allow a user to bypass authentication and retrieve data with specially crafted SQL queries.

References