CVE-2021-36205

CRITICAL

Under certain circumstances the session token is not cleared on logout.

Affects 3 products across 2 vendors.

BCS6.9
CVSS 3.19.8
EPSS1.0%
Percentile63th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity, no authentication required, no user interaction needed, impact contained to the vulnerable component, full confidentiality impact, full integrity impact, full availability impact.
CWE Weakness Definitions
CWE-459: CWE-459
◆ AI Analysis — automated analysis, not human-reviewed

A critical vulnerability exists in the session management mechanism where the session token is not cleared upon user logout, potentially allowing unauthorized access.

BSID: BS-2022-GLOBAL-297272-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2021-36205?
A critical vulnerability exists in the session management mechanism where the session token is not cleared upon user logout, potentially allowing unauthorized access.
What is the CVSS score for CVE-2021-36205?
CVE-2021-36205 has CVSS 9.8 (Critical). Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. EPSS: 1.0%.
Is CVE-2021-36205 actively exploited?
No confirmed active exploitation of CVE-2021-36205 as of 2026-09-25.
How do I remediate CVE-2021-36205?
Priority: IMMEDIATE. Advisory: https://www.johnsoncontrols.com/cyber-solutions/security-advisories PSIRT: [email protected]
What systems are affected by CVE-2021-36205?
CVE-2021-36205 affects: Johnsoncontrols, Johnsoncontrols, Johnsoncontrols, Michael K. Johnson.
Vulnerability Details
CVE IDCVE-2021-36205
BSIDBS-2022-GLOBAL-297272-C BreachSpider Global ID
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Published2022-04-15
Last Modified2026-06-17
ICS Relevance55%
Weakness (CWE)
SourceNVD
Official Description

Under certain circumstances the session token is not cleared on logout.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

An attacker could exploit this vulnerability by intercepting or guessing the session token of a logged-out user, thereby gaining unauthorized access to the user's account.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductAffected Versions
Johnsoncontrols Metasys Application And Data Server ≥ 10.0, < 10.1.5 ≥ 11.0, < 11.0.2
Johnsoncontrols Metasys Extended Application And Data Server ≥ 10.0, < 10.1.5 ≥ 11.0, < 11.0.2
Johnsoncontrols Metasys Open Application Server ≥ 10.0, < 10.1.5 ≥ 11.0, < 11.0.2
Michael K. Johnson &mdash; —
Remediation
View Vendor Advisory →

Remediation Priority: IMMEDIATE

Vendor PSIRT: [email protected]
Threat Intelligence
● Threat Intelligence Validated: October 2026 | Threat Age: 1629 Days
CISA KEVNot in KEV catalog
Public ExploitNot confirmed
PoC CodeNot confirmed
AI Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
SHA-512 Audit Hash126cb2942e494a7803c1512dce3fc5d2c554ca65141a4a29bd08760e168b82629bd38c928bd077a8c28e816c99eb9a0ef5827c3cbef0e654b745c74c8c4fbfdd
Related CVEs affecting Johnsoncontrols
CVE-2021-44228 10.0 Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2... CVE-2014-5428 10.0 Unrestricted file upload vulnerability in unspecified web services in Johnson... CVE-2021-27664 9.8 Under certain configurations an unauthenticated remote user could be given ac... CVE-2019-7589 9.8 A vulnerability with the SmartService API Service option exists whereby an un... CVE-2021-27663 9.8 A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems...
View all Johnsoncontrols CVEs →

Critical Severity - Know Your Exposure

A CVSS 9.8 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Create a free account →