Under some circumstances an Insufficiently Protected...
High severity
Unreviewed
Published
Jan 13, 2023
to the GitHub Advisory Database
•
Updated Jan 23, 2023
Description
Published by the National Vulnerability Database
Jan 13, 2023
Published to the GitHub Advisory Database
Jan 13, 2023
Last updated
Jan 23, 2023
Under some circumstances an Insufficiently Protected Credentials vulnerability in Johnson Controls Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.3 allows API calls to expose credentials in plain text.
References