Rewterz
Rewterz Threat Advisory – CVE-2021-39013 – IBM Cloud Pak for Security
December 23, 2021
Rewterz
Rewterz Threat Alert – Emotet – Active IOCs
December 23, 2021

Rewterz Threat Advisory – ICS: Johnson Controls American Dynamics VideoEdge

Severity

High

Analysis Summary

CVE-2021-36199

Johnson Controls American Dynamics VideoEdge is vulnerable to a denial of service, caused by a flaw when running a vulnerability scanner against VideoEdge NVRs. By sending a specially-crafted request, a remote attacker could exploit this vulnerability to cause some functionality to stop, and results in a denial of service condition.

Impact

  • Denial of Service

Affected Vendors

  • Johnson Controls

Affected Products

  • Johnson Controls American Dynamics VideoEdge 5.4.1
  • Johnson Controls American Dynamics VideoEdge 5.7.1

Remediation

Refer to Johnson Controls for patch, upgrade, or suggested workaround information.

https://www.johnsoncontrols.com/-/media/jci/cyber-solutions/product-security-advisories/2021/jci-psa-2021-21_videoedge-dos_v2.pdf?la=en&hash=A40F4E09C8545F2FB25C17242F7B14EA20475E65