Home
HIGH: 8.4 CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:NDefault status
unaffected
10.6 (custom) before release 10
affected
11.0 (custom) before release 9
affected
12 (custom) before release 3
affected
Description
Uncontrolled Search Path Element vulnerability in JohnsonControls AC2000 on Windows allows Leveraging/Manipulating Configuration File Search Paths. This issue affects AC2000: from 10.6 before release 10, from 11.0 before release 9, from 12 before release 3.
Problem types
CWE-427 Uncontrolled Search Path Element
Product status
10.6 (custom) before release 10
11.0 (custom) before release 9
12 (custom) before release 3
References
www.johnsoncontrols.com/...cybersecurity/security-advisories