Vulnerabilities > Johnsoncontrols > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-03-10 CVE-2020-9044 XXE vulnerability in Johnsoncontrols products
XXE vulnerability exists in the Metasys family of product Web Services which has the potential to facilitate DoS attacks or harvesting of ASCII server files.
network
low complexity
johnsoncontrols CWE-611
critical
9.1
2020-03-10 CVE-2019-7589 Improper Input Validation vulnerability in Johnsoncontrols Entrapass 7.60
A vulnerability with the SmartService API Service option exists whereby an unauthorized user could potentially exploit this to upload malicious code to the server that could be executed at system level privileges.
network
low complexity
johnsoncontrols CWE-20
critical
9.8
2019-08-20 CVE-2019-7594 Use of Hard-coded Credentials vulnerability in Johnsoncontrols Metasys System
Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a hardcoded RC2 key for certain encryption operations involving the Site Management Portal (SMP).
network
low complexity
johnsoncontrols CWE-798
critical
9.1
2019-08-20 CVE-2019-7593 Use of Hard-coded Credentials vulnerability in Johnsoncontrols Metasys System
Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a shared RSA key pair for certain encryption operations involving the Site Management Portal (SMP).
network
low complexity
johnsoncontrols CWE-798
critical
9.1