{"id":"CVE-2018-10624","title":"In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could allow an attacker to…","summary":"In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could allow an attacker to…","severity":"medium","cvss":4.3,"cvssVector":"CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N","cwe":["CWE-209","CWE-388"],"vendor":"johnsoncontrols","product":"bcpro","affected":["bcpro < 3.0.2","metasys_system <= 8.0"],"patched":["bcpro 3.0.2"],"published":"2018-08-01","updated":"2026-09-10","sourceUpdated":"2026-09-10T17:17:00.227","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2018-10624","references":[{"url":"http://www.securityfocus.com/bid/104937","label":"ics-cert@hq.dhs.gov"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-18-212-02","label":"ics-cert@hq.dhs.gov"},{"url":"http://www.securityfocus.com/bid/104937","label":"af854a3a-2127-422b-91ae-364da2661108"},{"url":"https://ics-cert.us-cert.gov/advisories/ICSA-18-212-02","label":"af854a3a-2127-422b-91ae-364da2661108"}],"tags":["nvd","cve.org"],"epss":0.00802,"epssPercentile":0.54671,"ingestedAt":"2026-09-10T18:02:18.296Z","slug":"CVE-2018-10624","body":"## Overview\n\nIn Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could allow an attacker to obtain technical information.\n\n## Affected\n\n- `bcpro < 3.0.2`\n- `metasys_system <= 8.0`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `bcpro 3.0.2`","depth":"sunlit","depthScore":24,"depthScoreParts":{"impact":23.7,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[]}