CVE-2021-27663

CRITICAL

A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems AC2000 allows a remote attacker to access to the system without adequate authorization. This issue affects: Johnson Con...

Affects 2 products across 2 vendors.

BCS7.34
CVSS 3.19.8
EPSS1.7%
Percentile76th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-285: CWE-285
Related Attack Patterns (CAPEC)
CAPEC-5 Blue Boxing
via CWE-285
CAPEC-13 Subverting Environment Variable Values
via CWE-285
CAPEC-45 Buffer Overflow via Symbolic Links
via CWE-285
CAPEC-51 Poison Web Service Registry
via CWE-285
CAPEC-59 Session Credential Falsification through Prediction
via CWE-285
Show all 17

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

A critical vulnerability in Johnson Controls CEM Systems AC2000 versions 10.1 through 10.5 allows unauthorized remote access to the system.

BSID: BS-2021-GLOBAL-268461-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2021-27663?
A critical vulnerability in Johnson Controls CEM Systems AC2000 versions 10.1 through 10.5 allows unauthorized remote access to the system.
What is the CVSS score for CVE-2021-27663?
CVE-2021-27663 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 1.7%.
Is CVE-2021-27663 actively exploited?
No confirmed active exploitation of CVE-2021-27663 as of 2026-09-25.
How do I remediate CVE-2021-27663?
Priority: IMMEDIATE. Advisory: https://www.johnsoncontrols.com/cyber-solutions/security-advisories PSIRT: [email protected]
What systems are affected by CVE-2021-27663?
CVE-2021-27663 affects: Johnsoncontrols, Johnsoncontrols, Michael K. Johnson.
Vulnerability Details
CVE IDCVE-2021-27663
BSIDBS-2021-GLOBAL-268461-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2021-08-30
Last Modified2026-06-17
ICS Relevance75%
Weakness (CWE)
SourceNVD
Official Description

A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems AC2000 allows a remote attacker to access to the system without adequate authorization. This issue affects: Johnson Controls CEM Systems AC2000 10.1; 10.2; 10.3; 10.4; 10.5.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability is exploited by sending specially crafted requests to the affected system, bypassing authentication mechanisms.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductAffected Versions
Johnsoncontrols Ac2000 Firmware ≥ 10.1, ≤ 10.5
Johnsoncontrols Ac2000 ≥ 10.1, ≤ 10.5
Michael K. Johnson — —
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: October 2026 | Threat Age: 1857 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
AI Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hashb6cd9c8e3f70099b486d87cc358478bf28c75ac70a5c8cebb00941641522b2037b8326c0d88bd86dc083f086a9245cf9b6f20435df5e9b969e09014a604f7011
Related CVEs affecting Johnsoncontrols
CVE-2021-44228 10.0 Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2... CVE-2014-5428 10.0 Unrestricted file upload vulnerability in unspecified web services in Johnson... CVE-2021-36205 9.8 Under certain circumstances the session token is not cleared on logout. CVE-2019-7589 9.8 A vulnerability with the SmartService API Service option exists whereby an un... CVE-2021-27664 9.8 Under certain configurations an unauthenticated remote user could be given ac...
View all Johnsoncontrols CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Create a free account →