johnsoncontrols kayıtları
johnsoncontrols üreticisine ait 80 yayımlanmış kayıt.
Araştırmacı profili
- KEV’e giren
- 0 · %0
- Silahlaştırılmış
- 0 · %0
- Pre-auth RCE
- 8
- Düzeltme kaydı olan
- %0
- Yayından KEV’e ortanca
- KEV’e giren kayıt yok
Tekrar eden sınıflar
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-269 Improper Privilege Management4
- CWE-20 Improper Input Validation4
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-287 Improper Authentication3
Bu üreticide en sık görülen zafiyet sınıfları: nereye bakmalı.
CWETüm kayıtlar
80 kayıt| Aksiyon | CVE | Zafiyet | Ciddiyet | KEV | EPSS | Yayın |
|---|---|---|---|---|---|---|
41Planlayın | CVE-2014-5428İstismar yok | Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used in Application and Djohnsoncontrols · metsys | Kritik10,0 | — | %3,9 | 29 Mar 2015 |
40Planlayın | CVE-2022-21941İstismar yok | All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauthenticated user root johnsoncontrols · istar ultra firmware · CWE-77 | Kritik9,8 | — | %2,1 | 31 Ağu 2022 |
40Planlayın | CVE-2021-27663İstismar yok | A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems AC2000 allows a remote attacker to access to the system withoujohnsoncontrols · ac2000 firmware · CWE-285 | Kritik9,8 | — | %1,7 | 30 Ağu 2021 |
39İzleyin | CVE-2019-7589İstismar yok | Kantech EntraPass Improper Input Validationjohnsoncontrols · entrapass · CWE-20 | Kritik9,8 | — | %1,6 | 10 Mar 2020 |
39İzleyin | CVE-2021-27664İstismar yok | exacqVision Web Servicejohnsoncontrols · exacqvision web service · CWE-269 | Kritik9,8 | — | %1,6 | 11 Eki 2021 |
39İzleyin | CVE-2021-36205İstismar yok | Metasys session tokenjohnsoncontrols · metasys application and data server · CWE-459 | Kritik9,8 | — | %1,0 | 15 Nis 2022 |
39İzleyin | CVE-2023-4804İstismar yok | An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.johnsoncontrols · quantum hd unity compressor firmware · CWE-489 | Kritik9,8 | — | %0,8 | 10 Kas 2023 |
39İzleyin | CVE-2023-0954İstismar yok | Debug feature in Sensormatic Electronics Illustra Dome and PTZ camerasjohnsoncontrols · illustra pro gen 4 dome firmware · CWE-489 | Kritik9,8 | — | %0,7 | 8 Haz 2023 |
39İzleyin | CVE-2024-0242İstismar yok | Unauthorized access to settings in Qolsys IQ Panel 4 and IQ4 Hubjohnsoncontrols · qolsys iq panel 4 firmware · CWE-200 | Kritik9,8 | — | %0,6 | 8 Şub 2024 |
39İzleyin | CVE-2023-3127İstismar yok | Improper Authentication in iSTARjohnsoncontrols · istar ultra firmware · CWE-287 | Kritik9,8 | — | %0,6 | 11 Tem 2023 |
39İzleyin | CVE-2023-3548İstismar yok | An unauthorized user could gain account access to IQ Wifi 6 versions prior to 2.0.2 by conducting a brute force authentication attack.johnsoncontrols · iq wifi 6 firmware · CWE-307 | Kritik9,8 | — | %0,6 | 25 Tem 2023 |
36İzleyin | CVE-2021-27660İstismar yok | An insecure client auto update feature in C-CURE 9000 can allow remote execution of lower privileged Windows programs.johnsoncontrols · c-cure 9000 firmware · CWE-20 | Yüksek8,8 | — | %2,1 | 1 Tem 2021 |
36İzleyin | CVE-2020-9044İstismar yok | Metasys Improper Restriction of XML External Entity Referencejohnsoncontrols · metasys application and data server · CWE-611 | Kritik9,1 | — | %1,3 | 10 Mar 2020 |
36İzleyin | CVE-2021-36203İstismar yok | Johnson Controls Metasys SCT Projohnsoncontrols · metasys system configuration tool · CWE-918 | Kritik9,1 | — | %0,9 | 22 Nis 2022 |
36İzleyin | CVE-2019-7593İstismar yok | Metasys use of shared RSA key pairsjohnsoncontrols · metasys system · CWE-323 | Kritik9,1 | — | %0,8 | 20 Ağu 2019 |
36İzleyin | CVE-2019-7594İstismar yok | Metasys use of hardcoded RC2 keyjohnsoncontrols · metasys system · CWE-321 | Kritik9,1 | — | %0,6 | 20 Ağu 2019 |
36İzleyin | CVE-2024-32755İstismar yok | American Dynamics Illustra Essentials Gen 4 - Log Filter Input Validationjohnson controls · american dynamics illustra essentials gen 4 · CWE-20 | Kritik9,1 | — | %0,5 | 2 Tem 2024 |
36İzleyin | CVE-2024-32758İstismar yok | exacqVision - Key exchangesjohnsoncontrols · exacqvision client · CWE-326 | Kritik9,0 | — | %0,4 | 1 Ağu 2024 |
35İzleyin | CVE-2026-21654İstismar yok | Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code Executionjohnsoncontrols · frick controls quantum hd firmware · CWE-78 | Yüksek8,8 | — | %1,5 | 27 Şub 2026 |
35İzleyin | CVE-2021-27657İstismar yok | Metasys Improper Privilege Managementjohnsoncontrols · metasys · CWE-269 | Yüksek8,8 | — | %1,2 | 4 Haz 2021 |
35İzleyin | CVE-2021-36207İstismar yok | Metasys privilege managementjohnsoncontrols · metasys application and data server · CWE-269 | Yüksek8,8 | — | %1,0 | 29 Nis 2022 |
35İzleyin | CVE-2022-21934İstismar yok | Metasys Unverified Password Changejohnsoncontrols · metasys application and data server · CWE-620 | Yüksek8,8 | — | %1,0 | 6 May 2022 |
35İzleyin | CVE-2021-27661İstismar yok | Successful exploitation of this vulnerability could give an authenticated Facility Explorer SNC Series Supervisory Controller (F4-SNC) user johnsoncontrols · f4-snc firmware · CWE-269 | Yüksek8,8 | — | %0,8 | 1 Tem 2021 |
35İzleyin | CVE-2021-36202İstismar yok | Server-Side Request Forgery (SSRF) vulnerability in Johnson Controls Metasys could allow an authenticated attacker to inject malicious code johnsoncontrols · metasys application and data server · CWE-918 | Yüksek8,8 | — | %0,8 | 7 Nis 2022 |
35İzleyin | CVE-2026-21658İstismar yok | Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code Executionjohnsoncontrols · frick controls quantum hd firmware · CWE-94 | Yüksek8,8 | — | %0,6 | 27 Şub 2026 |
- CVE-2014-542841Planlayın
Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used in Application and D
KritikCVSS 10,0İstismar yokEPSS %4johnsoncontrols · metsys29 Mar 2015
- CVE-2022-2194140Planlayın
All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauthenticated user root
KritikCVSS 9,8İstismar yokEPSS %2johnsoncontrols · istar ultra firmware31 Ağu 2022
- CVE-2021-2766340Planlayın
A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems AC2000 allows a remote attacker to access to the system withou
KritikCVSS 9,8İstismar yokEPSS %2johnsoncontrols · ac2000 firmware30 Ağu 2021
- CVE-2019-758939İzleyin
Kantech EntraPass Improper Input Validation
KritikCVSS 9,8İstismar yokEPSS %2johnsoncontrols · entrapass10 Mar 2020
- CVE-2021-2766439İzleyin
exacqVision Web Service
KritikCVSS 9,8İstismar yokEPSS %2johnsoncontrols · exacqvision web service11 Eki 2021
- CVE-2021-3620539İzleyin
Metasys session token
KritikCVSS 9,8İstismar yokEPSS %1johnsoncontrols · metasys application and data server15 Nis 2022
- CVE-2023-480439İzleyin
An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.
KritikCVSS 9,8İstismar yokEPSS %1johnsoncontrols · quantum hd unity compressor firmware10 Kas 2023
- CVE-2023-095439İzleyin
Debug feature in Sensormatic Electronics Illustra Dome and PTZ cameras
KritikCVSS 9,8İstismar yokEPSS %1johnsoncontrols · illustra pro gen 4 dome firmware8 Haz 2023
- CVE-2024-024239İzleyin
Unauthorized access to settings in Qolsys IQ Panel 4 and IQ4 Hub
KritikCVSS 9,8İstismar yokEPSS %1johnsoncontrols · qolsys iq panel 4 firmware8 Şub 2024
- CVE-2023-312739İzleyin
Improper Authentication in iSTAR
KritikCVSS 9,8İstismar yokEPSS %1johnsoncontrols · istar ultra firmware11 Tem 2023
- CVE-2023-354839İzleyin
An unauthorized user could gain account access to IQ Wifi 6 versions prior to 2.0.2 by conducting a brute force authentication attack.
KritikCVSS 9,8İstismar yokEPSS %1johnsoncontrols · iq wifi 6 firmware25 Tem 2023
- CVE-2021-2766036İzleyin
An insecure client auto update feature in C-CURE 9000 can allow remote execution of lower privileged Windows programs.
YüksekCVSS 8,8İstismar yokEPSS %2johnsoncontrols · c-cure 9000 firmware1 Tem 2021
- CVE-2020-904436İzleyin
Metasys Improper Restriction of XML External Entity Reference
KritikCVSS 9,1İstismar yokEPSS %1johnsoncontrols · metasys application and data server10 Mar 2020
- CVE-2021-3620336İzleyin
Johnson Controls Metasys SCT Pro
KritikCVSS 9,1İstismar yokEPSS %1johnsoncontrols · metasys system configuration tool22 Nis 2022
- CVE-2019-759336İzleyin
Metasys use of shared RSA key pairs
KritikCVSS 9,1İstismar yokEPSS %1johnsoncontrols · metasys system20 Ağu 2019
- CVE-2019-759436İzleyin
Metasys use of hardcoded RC2 key
KritikCVSS 9,1İstismar yokEPSS %1johnsoncontrols · metasys system20 Ağu 2019
- CVE-2024-3275536İzleyin
American Dynamics Illustra Essentials Gen 4 - Log Filter Input Validation
KritikCVSS 9,1İstismar yokEPSS %1johnson controls · american dynamics illustra essentials gen 42 Tem 2024
- CVE-2024-3275836İzleyin
exacqVision - Key exchanges
KritikCVSS 9,0İstismar yokEPSS %0johnsoncontrols · exacqvision client1 Ağu 2024
- CVE-2026-2165435İzleyin
Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code Execution
YüksekCVSS 8,8İstismar yokEPSS %2johnsoncontrols · frick controls quantum hd firmware27 Şub 2026
- CVE-2021-2765735İzleyin
Metasys Improper Privilege Management
YüksekCVSS 8,8İstismar yokEPSS %1johnsoncontrols · metasys4 Haz 2021
- CVE-2021-3620735İzleyin
Metasys privilege management
YüksekCVSS 8,8İstismar yokEPSS %1johnsoncontrols · metasys application and data server29 Nis 2022
- CVE-2022-2193435İzleyin
Metasys Unverified Password Change
YüksekCVSS 8,8İstismar yokEPSS %1johnsoncontrols · metasys application and data server6 May 2022
- CVE-2021-2766135İzleyin
Successful exploitation of this vulnerability could give an authenticated Facility Explorer SNC Series Supervisory Controller (F4-SNC) user
YüksekCVSS 8,8İstismar yokEPSS %1johnsoncontrols · f4-snc firmware1 Tem 2021
- CVE-2021-3620235İzleyin
Server-Side Request Forgery (SSRF) vulnerability in Johnson Controls Metasys could allow an authenticated attacker to inject malicious code
YüksekCVSS 8,8İstismar yokEPSS %1johnsoncontrols · metasys application and data server7 Nis 2022
- CVE-2026-2165835İzleyin
Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code Execution
YüksekCVSS 8,8İstismar yokEPSS %1johnsoncontrols · frick controls quantum hd firmware27 Şub 2026