Metasys ADS/ADX/OAS with MUI
CVE-2021-36200

5.3MEDIUM

Key Information:

Vendor
CVE Published:
22 July 2022

What is CVE-2021-36200?

Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.2 and enumerate users.

Affected Version(s)

Metasys ADS/ADX/OAS server All 10 versions < 10.1.6

Metasys ADS/ADX/OAS server All 11 versions < 11.0.2

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Alessandro Bosco, Luca Di Giuseppe, Stefano Scipioni, and Massimiliano Brolli of TIM Security Red Team Research
.