Vulnerabilities > Johnsoncontrols

DATE CVE VULNERABILITY TITLE RISK
2020-05-21 CVE-2020-9045 Cleartext Storage of Sensitive Information vulnerability in multiple products
During installation or upgrade to Software House C•CURE 9000 v2.70 and American Dynamics victor Video Management System v5.2, the credentials of the user used to perform the installation or upgrade are logged in a file.
network
low complexity
tyco johnsoncontrols CWE-312
6.5
2020-03-10 CVE-2020-9044 XXE vulnerability in Johnsoncontrols products
XXE vulnerability exists in the Metasys family of product Web Services which has the potential to facilitate DoS attacks or harvesting of ASCII server files.
network
low complexity
johnsoncontrols CWE-611
6.4
2020-03-10 CVE-2019-7589 Improper Input Validation vulnerability in Johnsoncontrols Entrapass 7.60
A vulnerability with the SmartService API Service option exists whereby an unauthorized user could potentially exploit this to upload malicious code to the server that could be executed at system level privileges.
network
low complexity
johnsoncontrols CWE-20
critical
10.0
2019-08-20 CVE-2019-7594 Use of Hard-coded Credentials vulnerability in Johnsoncontrols Metasys System
Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a hardcoded RC2 key for certain encryption operations involving the Site Management Portal (SMP).
network
low complexity
johnsoncontrols CWE-798
6.4
2019-08-20 CVE-2019-7593 Use of Hard-coded Credentials vulnerability in Johnsoncontrols Metasys System
Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a shared RSA key pair for certain encryption operations involving the Site Management Portal (SMP).
network
low complexity
johnsoncontrols CWE-798
6.4
2019-07-19 CVE-2019-7590 Unquoted Search Path or Element vulnerability in Johnsoncontrols Exacqvision Server 9.6/9.8
ExacqVision Server’s services 'exacqVisionServer', 'dvrdhcpserver' and 'mdnsresponder' have an unquoted service path.
local
low complexity
johnsoncontrols CWE-428
4.6
2018-08-01 CVE-2018-10624 7PK - Errors vulnerability in Johnsoncontrols Bcpro and Metasys System
In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could allow an attacker to obtain technical information.
low complexity
johnsoncontrols CWE-388
6.5
2015-03-29 CVE-2014-5428 Unspecified vulnerability in Johnsoncontrols Metsys 4.1/6.5
Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote attackers to execute arbitrary code by uploading a shell script.
network
low complexity
johnsoncontrols
critical
10.0
2015-03-29 CVE-2014-5427 Information Exposure vulnerability in Johnsoncontrols Metsys 4.1/6.5
Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote attackers to read password hashes via a POST request.
network
low complexity
johnsoncontrols CWE-200
5.0
2012-07-16 CVE-2012-4026 Improper Input Validation vulnerability in Johnsoncontrols products
The Johnson Controls Pegasys P2000 server with software before 3.11 allows remote attackers to trigger false alerts via crafted packets to TCP port 41013 (aka the upload port), a different vulnerability than CVE-2012-2607.
network
low complexity
johnsoncontrols CWE-20
5.0