Johnsoncontrols
johnsoncontrols
68 CVEs • 113 products
Products (113)
Click to collapseToggle
Products (113)
Click to collapse
CVEs (68)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Johnsoncontrols 1Metasys System Jun 17, 2026 Aug 20, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a hardcoded RC2 key for certain encryption operations involving the Site Management Portal (SMP). |
1Johnsoncontrols 1Metasys System Jun 17, 2026 Aug 20, 2019 N/A· v4 9.1 CRITICAL· v3 6.4 MEDIUM· v2 Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a shared RSA key pair for certain encryption operations involving the Site Management Portal (SMP). |
1Johnsoncontrols 1Exacqvision Server Jun 17, 2026 Jul 19, 2019 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 ExacqVision Server’s services 'exacqVisionServer', 'dvrdhcpserver' and 'mdnsresponder' have an unquoted service path. If an authenticated user is able to insert code in their system root path it potentially can be execut...Show more |
1Johnsoncontrols 2Bcpro Metasys SystemNov 21, 2024 Aug 1, 2018 N/A· v4 6.5 MEDIUM· v3 3.3 LOW· v2 In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could all...Show more |
Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Contr...Show more |
Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network...Show more |
1Johnsoncontrols 2Pegasys P2000 Server Pegasys P2000 Server SoftwareApr 29, 2026 Jul 16, 2012 N/A· v4 N/A· v3 5.0 MEDIUM· v2 The Johnson Controls Pegasys P2000 server with software before 3.11 allows remote attackers to trigger false alerts via crafted packets to TCP port 41013 (aka the upload port), a different vulnerability than CVE-2012-260...Show more |
1Johnsoncontrols 2Network Controller Network Controller FirmwareApr 29, 2026 Jul 16, 2012 N/A· v4 N/A· v3 7.5 HIGH· v2 The Johnson Controls CK721-A controller with firmware before SSM4388_03.1.0.14_BB allows remote attackers to perform arbitrary actions via crafted packets to TCP port 41014 (aka the download port). |