Johnsoncontrols
johnsoncontrols
72 CVEs • 115 products
Products (115)
Click to collapseToggle
Products (115)
Click to collapse
CVEs (72)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Johnsoncontrols 1Kantech Entrapass Jun 17, 2026 May 26, 2020 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 A vulnerability in all versions of Kantech EntraPass Editions could potentially allow an authorized low-privileged user to gain full system-level privileges by replacing critical files with specifically crafted files. |
2Johnsoncontrols Tyco2C Cure 9000 Firmware Victor Video Management SystemJun 17, 2026 May 21, 2020 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 During installation or upgrade to Software House C•CURE 9000 v2.70 and American Dynamics victor Video Management System v5.2, the credentials of the user used to perform the installation or upgrade are logged in a file....Show more |
1Johnsoncontrols 13Metasys Application And Data Server Metasys Extended Application And Data ServerMetasys Lonworks Control Server+10 moreJun 17, 2026 Mar 10, 2020 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 XXE vulnerability exists in the Metasys family of product Web Services which has the potential to facilitate DoS attacks or harvesting of ASCII server files. This affects Johnson Controls' Metasys Application and Data Se...Show more |
A vulnerability with the SmartService API Service option exists whereby an unauthorized user could potentially exploit this to upload malicious code to the server that could be executed at system level privileges. This a...Show more |
1Johnsoncontrols 1Metasys System Jun 17, 2026 Aug 20, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a hardcoded RC2 key for certain encryption operations involving the Site Management Portal (SMP). |
1Johnsoncontrols 1Metasys System Jun 17, 2026 Aug 20, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a shared RSA key pair for certain encryption operations involving the Site Management Portal (SMP). |
1Johnsoncontrols 1Exacqvision Server Jun 17, 2026 Jul 19, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 ExacqVision Server’s services 'exacqVisionServer', 'dvrdhcpserver' and 'mdnsresponder' have an unquoted service path. If an authenticated user is able to insert code in their system root path it potentially can be execut...Show more |
1Johnsoncontrols 2Bcpro Metasys SystemNov 21, 2024 Aug 1, 2018 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could all...Show more |
Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Contr...Show more |
Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network...Show more |
1Johnsoncontrols 2Pegasys P2000 Server Pegasys P2000 Server SoftwareApr 29, 2026 Jul 16, 2012 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The Johnson Controls Pegasys P2000 server with software before 3.11 allows remote attackers to trigger false alerts via crafted packets to TCP port 41013 (aka the upload port), a different vulnerability than CVE-2012-260...Show more |
1Johnsoncontrols 2Network Controller Network Controller FirmwareApr 29, 2026 Jul 16, 2012 N/A· v4 N/A· v3 7.5 HIGH· v2 The Johnson Controls CK721-A controller with firmware before SSM4388_03.1.0.14_BB allows remote attackers to perform arbitrary actions via crafted packets to TCP port 41014 (aka the download port). |