CVE-2018-10624

Executive Summary

CVE-2018-10624 affects Johnson Controls Metasys System v8.0 and earlier, and BCPro (BCM) versions before 3.0.2. The flaw stems from improper error handling in HTTP-based server communications, enabling attackers to trigger responses that leak technical details about the system. While not listed in CISA KEV, the vulnerability could aid reconnaissance or further exploitation by exposing configuration or version information.


Authoritative CVE Metadata - CVSS Base Score: 4.3 (MEDIUM) - Published: 2018-08-01T21:29:00.217 - Last Modified: 2026-09-10T17:17:00.227

Original Description: In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could allow an attacker to obtain technical information.

"We are all inclined to judge ourselves by our ideals; others, by their acts."

— Harold Nicolson
Source: NVD