Successful exploitation of this vulnerability, discovered by Kim Syversen and Mathias Kjølleberg Førland who reported this vulnerability to Johnson Controls, could allow an unauthorized user to enumerate user accounts.
Johnson Controls Inc. reports this vulnerability affects the following Sensormatic Electronics C-CURE 9000 security management systems: C-CURE 9000 version 2.90 and prior.
In the vulnerability, Sensormatic Electronics C•CURE 9000, version 2.90 and prior, provides responses to incoming requests that could reveal internal state information to an unauthorized user.
CVE-2021-36201 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 4.3.
The product sees use mainly in the critical manufacturing sector, and on a global basis.
No known public exploits specifically target this vulnerability. This vulnerability is not exploitable remotely. This vulnerability has a low attack complexity.
Johnson Controls recommends users update or upgrade to one of the two versions below:
- Update C-CURE 9000 2.90 with patch 2.90 SP5Â
- Upgrade C-CURE 9000 to version 3.0Â
For more detailed mitigation instructions, click on Johnson Controls Product Security Advisory JCI-PSA-2022-12 v1.

