High severity8.8NVD Advisory· Published Jul 1, 2021· Updated Jun 17, 2026
CVE-2021-27660
CVE-2021-27660
Description
An insecure client auto update feature in C-CURE 9000 can allow remote execution of lower privileged Windows programs.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- cpe:2.3:o:johnsoncontrols:c-cure_9000_firmware:*:*:*:*:*:*:*:*Range: <2.80
- Range: All versions of C-CURE 9000 prior to 2.80
Patches
Vulnerability mechanics
References
2- us-cert.cisa.gov/ics/advisories/icsa-21-182-02nvdThird Party AdvisoryUS Government Resource
- www.johnsoncontrols.com/cyber-solutions/security-advisoriesnvdVendor Advisory
News mentions
0No linked articles in our index yet.