← Back

CVE-2020-9044

nvd nist
Published: Mar 10, 2020Modified: Jun 17, 2026

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Exploitability: 3.9 / Impact: 5.2
Source: NVD

Description

XXE vulnerability exists in the Metasys family of product Web Services which has the potential to facilitate DoS attacks or harvesting of ASCII server files. This affects Johnson Controls' Metasys Application and Data Server (ADS, ADS-Lite) versions 10.1 and prior; Metasys Extended Application and Data Server (ADX) versions 10.1 and prior; Metasys Open Data Server (ODS) versions 10.1 and prior; Metasys Open Application Server (OAS) version 10.1; Metasys Network Automation Engine (NAE55 only) versions 9.0.1, 9.0.2, 9.0.3, 9.0.5, 9.0.6; Metasys Network Integration Engine (NIE55/NIE59) versions 9.0.1, 9.0.2, 9.0.3, 9.0.5, 9.0.6; Metasys NAE85 and NIE85 versions 10.1 and prior; Metasys LonWorks Control Server (LCS) versions 10.1 and prior; Metasys System Configuration Tool (SCT) versions 13.2 and prior; Metasys Smoke Control Network Automation Engine (NAE55, UL 864 UUKL/ORD-C100-13 UUKLC 10th Edition Listed) version 8.1.

Affected (27)

13 products
Metasys Lonworks Control Server
Metasys Open Application Server
Metasys Open Data Server
Metasys System Configuration Tool
Nae55 Firmware
Nie55 Firmware
Nie59 Firmware
Nae85 Firmware
Nie85 Firmware
Ul 864 Uukl Firmware
Ord C100 13 Uuklc Firmware
Configuration A
7 vulnerable
Configuration B
5 vulnerable
Vulnerable SoftwareAffected Versions
Johnsoncontrols
Version 9.0.1
Version 9.0.2
Version 9.0.3
Version 9.0.5
Version 9.0.6
Configuration C
5 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Johnsoncontrols
Version 9.0.1
Version 9.0.2
Version 9.0.3
Version 9.0.5
Version 9.0.6
Running on/withPlatform Versions
Johnsoncontrols
Nie55
All versions
Configuration D
5 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Johnsoncontrols
Version 9.0.1
Version 9.0.2
Version 9.0.3
Version 9.0.5
Version 9.0.6
Running on/withPlatform Versions
Johnsoncontrols
Nie59
All versions
Configuration E
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 10.1
Running on/withPlatform Versions
Johnsoncontrols
Nae85
All versions
Configuration F
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 10.1
Running on/withPlatform Versions
Johnsoncontrols
Nie85
All versions
Configuration G
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 8.1
Running on/withPlatform Versions
Johnsoncontrols
Nae55
All versions
Configuration H
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 8.1
Running on/withPlatform Versions
Johnsoncontrols
Ul 864 Uukl
All versions
Configuration I
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 8.1
Running on/withPlatform Versions
Johnsoncontrols
Ord C100 13 Uuklc
All versions

References (4)

Source: productsecurity@jci.com
Vendor Advisory
Source: productsecurity@jci.com
Third Party AdvisoryUS Government Resource
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryUS Government Resource

Timeline

No history available yet.