CVE-2018-10624: Johnsoncontrols Bcpro

Medium severity, CVSS 4.3. EPSS: 0.9% chance of exploitation in the next 30 days.

In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could allow an attacker to obtain technical information.

Affected products

Published 2018-08-01. Last modified 2026-09-10.