CVE-2021-27664

CRITICAL

Under certain configurations an unauthenticated remote user could be given access to credentials stored in the exacqVision Server.

Affects 1 product across 2 vendors.

BCS6.89
CVSS 3.19.8
EPSS1.6%
Percentile75th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-269: Improper Privilege Management

Software does not properly assign, modify, track, or check privileges, allowing unauthorized elevation of access.

Related Attack Patterns (CAPEC)
CAPEC-58 Restful Privilege Elevation
via CWE-269
CAPEC-122 Privilege Abuse
via CWE-269
CAPEC-233 Privilege Escalation
via CWE-269

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ AI Analysis — automated analysis, not human-reviewed

An unauthenticated remote user could gain access to stored credentials in the exacqVision Server under specific configurations, posing a significant security risk.

BSID: BS-2021-GLOBAL-074192-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2021-27664?
An unauthenticated remote user could gain access to stored credentials in the exacqVision Server under specific configurations, posing a significant security risk.
What is the CVSS score for CVE-2021-27664?
CVE-2021-27664 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 1.6%.
Is CVE-2021-27664 actively exploited?
No confirmed active exploitation of CVE-2021-27664 as of 2026-09-25.
How do I remediate CVE-2021-27664?
Priority: IMMEDIATE. Advisory: https://www.johnsoncontrols.com/cyber-solutions/security-advisories PSIRT: [email protected]
What systems are affected by CVE-2021-27664?
CVE-2021-27664 affects: Johnsoncontrols, Michael K. Johnson.
Vulnerability Details
CVE IDCVE-2021-27664
BSIDBS-2021-GLOBAL-074192-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2021-10-11
Last Modified2026-06-17
ICS Relevance70%
Weakness (CWE)
SourceNVD
Official Description

Under certain configurations an unauthenticated remote user could be given access to credentials stored in the exacqVision Server.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability allows an attacker to exploit a misconfiguration in the exacqVision Server, enabling unauthorized access to sensitive credentials without requiring authentication.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductAffected Versions
Johnsoncontrols Exacqvision Web Service ≤ 20.06.11.0 ≥ 21.06.11.0, ≤ 21.06.11.0
Michael K. Johnson — —
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: October 2026 | Threat Age: 1815 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
AI Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash2e54628c82fa06ae4aadd60ad8453add161ca4ea7b22013253e31b787fae35c0c309df32437509bee579aad53fdbc0edf3eabb2cd55fe79ab97c02992d64b3ab
Related CVEs affecting Johnsoncontrols
CVE-2021-44228 10.0 Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2... CVE-2014-5428 10.0 Unrestricted file upload vulnerability in unspecified web services in Johnson... CVE-2021-36205 9.8 Under certain circumstances the session token is not cleared on logout. CVE-2019-7589 9.8 A vulnerability with the SmartService API Service option exists whereby an un... CVE-2021-27663 9.8 A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems...
View all Johnsoncontrols CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Create a free account →