{"api_version":"v1","generated_at":"2026-10-08T14:05:00+00:00","product":{"cve_count":4,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-johnson-controls-metasys-a12cdcb59e12","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"Metasys","next_cursor":null,"observations":[{"affected":"Application and Data Server (ADS) installed with SQL Express deployed as part of the Metasys 14.1 and prior installation; Extended Application and Data Server (ADX) installed with SQL Express deployed as part of the Metasys 14.1 installation; LCS8500 or NAE8500 installed with SQL Express deployed as part of the Metasys installation Releases 12.0 through 14.1; System Configuration Tool (SCT) installed with SQL Express deployed as part of the SCT installation 17.1 and prior; Controller Configuration Tool (CCT) installed with SQL Express deployed as part of the CCT installation 17.0 and prior","affected_versions_present":true,"cve_id":"CVE-2025-26385","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-26385","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-01-30T12:38:11.405Z","patch_url":"","primary_source":"","published":"2026-01-30T11:05:16.688Z"},{"affected":"All 10 versions < 10.1.5; All 11 versions < 11.0.2","affected_versions_present":true,"cve_id":"CVE-2021-36205","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-36205","fixed":"[\u30d1\u30c3\u30c1\u3092\u9069\u7528\u3059\u308b] \u958b\u767a\u8005\u304c\u63d0\u4f9b\u3059\u308b\u60c5\u5831\u3092\u3082\u3068\u306b\u30d1\u30c3\u30c1\u3092\u9069\u7528\u3057\u3066\u304f\u3060\u3055\u3044\u3002 \u958b\u767a\u8005\u306f\u672c\u8106\u5f31\u6027\u306e\u5bfe\u7b56\u3068\u3057\u3066\u6b21\u306e\u30d1\u30c3\u30c1\u3092\u30ea\u30ea\u30fc\u30b9\u3057\u3066\u3044\u307e\u3059\u3002 * Metasys ADS/ADX/OAS Version 10 with patch 10.1.5 * Metasys ADS/ADX/OAS Version 11 with patch 11.0.2","last_modified":"2024-09-16T23:41:01.659Z","patch_url":"https://jvndb.jvn.jp/ja/contents/2022/JVNDB-2022-001543.html","primary_source":"","published":"2022-04-15T16:24:48.570Z"},{"affected":"All 10 versions < 10.1.5; All 11 versions < 11.0.2","affected_versions_present":true,"cve_id":"CVE-2021-36202","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-36202","fixed":"[\u30d1\u30c3\u30c1\u3092\u9069\u7528\u3059\u308b] \u958b\u767a\u8005\u304c\u63d0\u4f9b\u3059\u308b\u60c5\u5831\u3092\u3082\u3068\u306b\u30d1\u30c3\u30c1\u3092\u9069\u7528\u3057\u3066\u304f\u3060\u3055\u3044\u3002 \u958b\u767a\u8005\u306f\u672c\u8106\u5f31\u6027\u306e\u5bfe\u7b56\u3068\u3057\u3066\u6b21\u306e\u30d1\u30c3\u30c1\u3092\u30ea\u30ea\u30fc\u30b9\u3057\u3066\u3044\u307e\u3059\u3002 * Metasys ADS/ADX/OAS Version 10 with patch 10.1.5 * Metasys ADS/ADX/OAS Version 11 with patch 11.0.2","last_modified":"2024-09-17T01:50:52.203Z","patch_url":"https://jvndb.jvn.jp/ja/contents/2022/JVNDB-2022-001517.html","primary_source":"","published":"2022-04-07T19:12:48.421Z"},{"affected":"11.0 \u2264 11.0","affected_versions_present":true,"cve_id":"CVE-2021-27657","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-27657","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-09-17T00:51:44.651Z","patch_url":"","primary_source":"","published":"2021-06-04T14:07:39.073Z"}],"source_generated_at":"2026-10-08T06:18:52.353Z","vendor":"Johnson Controls"}}
