← Back

Johnsoncontrols

johnsoncontrols

68 CVEs • 113 products

Products (113)

Click to collapse
Toggle
Metsys
metsys
Videoedge
videoedge
Bcpro
bcpro
Entrapass
entrapass
Nie55 Firmware
nie55_firmware
Nie59 Firmware
nie59_firmware
Nae85 Firmware
nae85_firmware
Nie85 Firmware
nie85_firmware
C Cure Web
c-cure_web
Victor Web
victor_web
Metasys
metasys
Cevas
cevas
Nxe8500
nxe8500
Nae55
nae55
Nie55
nie55
Nie59
nie59
Nae85
nae85
Nie85
nie85
Ul 864 Uukl
ul_864_uukl
C Cure 9000
c-cure_9000
F4 Snc
f4-snc
Ac2000
ac2000
Istar Ultra
istar_ultra
Edge G2
edge_g2
Iq Wifi 6
iq_wifi_6

CVEs (68)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Johnsoncontrols
2Illustra Pro Gen 4 Dome Firmware
Illustra Pro Gen 4 Ptz Firmware
Jun 17, 2026
Jun 8, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A debug feature in Sensormatic Electronics Illustra Pro Gen 4 Dome and PTZ cameras allows a user to compromise credentials after a long period of sustained attack.
1Johnsoncontrols
1Openblue Enterprise Manager Data Collector
Jun 17, 2026
May 18, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 may expose sensitive information to an unauthorized user under certain circumstances.
1Johnsoncontrols
1Openblue Enterprise Manager Data Collector
Jun 17, 2026
May 18, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unauthorized user under certain circumstances.
1Johnsoncontrols
1Metasys System Configuration Tool
Jun 17, 2026
Feb 9, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.
1Johnsoncontrols
1Metasys System Configuration Tool
Jun 17, 2026
Feb 9, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.
1Johnsoncontrols
3Metasys Application And Data Server
Metasys Extended Application And Data ServerMetasys Open Application Server
Jun 17, 2026
Jan 13, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
Under some circumstances an Insufficiently Protected Credentials vulnerability in Johnson Controls Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.3 allows API calls to expose credentials in...Show more
Under some circumstances an Insufficiently Protected Credentials vulnerability in Johnson Controls Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.3 allows API calls to expose credentials in plain text.Show less
1Johnsoncontrols
1Cevas
Jun 17, 2026
Oct 28, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
All versions of CEVAS prior to 1.01.46 do not sufficiently validate user-controllable input and could allow a user to bypass authentication and retrieve data with specially crafted SQL queries.
1Johnsoncontrols
1C Cure 9000 Firmware
Jun 17, 2026
Oct 11, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Under certain circumstances a CCURE Portal user could enumerate user accounts in CCURE 9000 version 2.90 and prior versions.
1Johnsoncontrols
1Metasys Extended Application And Data Server
Jun 17, 2026
Oct 7, 2022
N/A· v4
6.5 MEDIUM· v3
N/A· v2
On Metasys ADX Server version 12.0 running MVE, an Active Directory user could execute validated actions without providing a valid password when using MVE SMP UI.
1Johnsoncontrols
1Istar Ultra Firmware
Jun 17, 2026
Aug 31, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauthenticated user root access to the system.
1Johnsoncontrols
3Metasys Application And Data Server
Metasys Extended Application And Data ServerMetasys Open Application Server
Jun 17, 2026
Jul 22, 2022
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.2 and enumerate users.
1Johnsoncontrols
3Metasys Application And Data Server
Metasys Extended Application And Data ServerMetasys Open Application Server
Jun 17, 2026
Jun 15, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 could allow a user to inject malicious code into the MUI Graphics web in...Show more
Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 could allow a user to inject malicious code into the MUI Graphics web interface.Show less
1Johnsoncontrols
3Metasys Application And Data Server
Metasys Extended Application And Data ServerMetasys Open Application Server
Jun 17, 2026
Jun 15, 2022
N/A· v4
5.4 MEDIUM· v3
2.1 LOW· v2
Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 could allow a user to inject malicious code into the web interface.
1Johnsoncontrols
3Metasys Application And Data Server
Metasys Extended Application And Data ServerMetasys Open Application Server
Jun 17, 2026
Jun 15, 2022
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 allows unverified password change.
1Johnsoncontrols
3Metasys Application And Data Server
Metasys Extended Application And Data ServerMetasys Open Application Server
Jun 17, 2026
May 6, 2022
N/A· v4
8.8 HIGH· v3
6.0 MEDIUM· v2
Under certain circumstances an authenticated user could lock other users out of the system or take over their accounts in Metasys ADS/ADX/OAS server 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS server 11 versions...Show more
Under certain circumstances an authenticated user could lock other users out of the system or take over their accounts in Metasys ADS/ADX/OAS server 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS server 11 versions prior to 11.0.2.Show less
1Johnsoncontrols
3Metasys Application And Data Server
Metasys Extended Application And Data ServerMetasys Open Application Server
Jun 17, 2026
Apr 29, 2022
N/A· v4
8.8 HIGH· v3
8.5 HIGH· v2
Under certain circumstances improper privilege management in Metasys ADS/ADX/OAS servers versions 10 and 11 could allow an authenticated user to elevate their privileges to administrator.
1Johnsoncontrols
1Metasys System Configuration Tool
Jun 17, 2026
Apr 22, 2022
N/A· v4
9.1 CRITICAL· v3
6.4 MEDIUM· v2
The affected product may allow an attacker to identify and forge requests to internal systems by way of a specially crafted request.
1Johnsoncontrols
3Metasys Application And Data Server
Metasys Extended Application And Data ServerMetasys Open Application Server
Jun 17, 2026
Apr 15, 2022
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
Under certain circumstances the session token is not cleared on logout.
1Johnsoncontrols
1Easyio Cpt Graphics
Jul 9, 2026
Apr 13, 2022
N/A· v4
5.3 MEDIUM· v3
5.0 MEDIUM· v2
An issue in EasyIO CPT Graphics v0.8 allows attackers to discover valid users in the application.
1Johnsoncontrols
3Metasys Application And Data Server
Metasys Extended Application And Data ServerMetasys Open Application Server
Jun 17, 2026
Apr 7, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Server-Side Request Forgery (SSRF) vulnerability in Johnson Controls Metasys could allow an authenticated attacker to inject malicious code into the MUI PDF export feature. This issue affects: Johnson Controls Metasys Al...Show more
Server-Side Request Forgery (SSRF) vulnerability in Johnson Controls Metasys could allow an authenticated attacker to inject malicious code into the MUI PDF export feature. This issue affects: Johnson Controls Metasys All 10 versions versions prior to 10.1.5; All 11 versions versions prior to 11.0.2.Show less