Skip to content
Noroxi

johnsoncontrols records

80 published records for vendor johnsoncontrols.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
8
With a fix record
0%
Median publish → KEV
No record has entered KEV

All records

80 records
  • Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used in Application and D

    CriticalCVSS 10.0No exploitEPSS 4%

    johnsoncontrols · metsysMar 29, 2015

  • All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauthenticated user root

    CriticalCVSS 9.8No exploitEPSS 2%

    johnsoncontrols · istar ultra firmwareAug 31, 2022

  • A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems AC2000 allows a remote attacker to access to the system withou

    CriticalCVSS 9.8No exploitEPSS 2%

    johnsoncontrols · ac2000 firmwareAug 30, 2021

  • CVE-2019-7589
    39Monitor

    Kantech EntraPass Improper Input Validation

    CriticalCVSS 9.8No exploitEPSS 2%

    johnsoncontrols · entrapassMar 10, 2020

  • exacqVision Web Service

    CriticalCVSS 9.8No exploitEPSS 2%

    johnsoncontrols · exacqvision web serviceOct 11, 2021

  • Metasys session token

    CriticalCVSS 9.8No exploitEPSS 1%

    johnsoncontrols · metasys application and data serverApr 15, 2022

  • CVE-2023-4804
    39Monitor

    An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.

    CriticalCVSS 9.8No exploitEPSS 1%

    johnsoncontrols · quantum hd unity compressor firmwareNov 10, 2023

  • CVE-2023-0954
    39Monitor

    Debug feature in Sensormatic Electronics Illustra Dome and PTZ cameras

    CriticalCVSS 9.8No exploitEPSS 1%

    johnsoncontrols · illustra pro gen 4 dome firmwareJun 8, 2023

  • CVE-2024-0242
    39Monitor

    Unauthorized access to settings in Qolsys IQ Panel 4 and IQ4 Hub

    CriticalCVSS 9.8No exploitEPSS 1%

    johnsoncontrols · qolsys iq panel 4 firmwareFeb 8, 2024

  • CVE-2023-3127
    39Monitor

    Improper Authentication in iSTAR

    CriticalCVSS 9.8No exploitEPSS 1%

    johnsoncontrols · istar ultra firmwareJul 11, 2023

  • CVE-2023-3548
    39Monitor

    An unauthorized user could gain account access to IQ Wifi 6 versions prior to 2.0.2 by conducting a brute force authentication attack.

    CriticalCVSS 9.8No exploitEPSS 1%

    johnsoncontrols · iq wifi 6 firmwareJul 25, 2023

  • An insecure client auto update feature in C-CURE 9000 can allow remote execution of lower privileged Windows programs.

    HighCVSS 8.8No exploitEPSS 2%

    johnsoncontrols · c-cure 9000 firmwareJul 1, 2021

  • CVE-2020-9044
    36Monitor

    Metasys Improper Restriction of XML External Entity Reference

    CriticalCVSS 9.1No exploitEPSS 1%

    johnsoncontrols · metasys application and data serverMar 10, 2020

  • Johnson Controls Metasys SCT Pro

    CriticalCVSS 9.1No exploitEPSS 1%

    johnsoncontrols · metasys system configuration toolApr 22, 2022

  • CVE-2019-7593
    36Monitor

    Metasys use of shared RSA key pairs

    CriticalCVSS 9.1No exploitEPSS 1%

    johnsoncontrols · metasys systemAug 20, 2019

  • CVE-2019-7594
    36Monitor

    Metasys use of hardcoded RC2 key

    CriticalCVSS 9.1No exploitEPSS 1%

    johnsoncontrols · metasys systemAug 20, 2019

  • American Dynamics Illustra Essentials Gen 4 - Log Filter Input Validation

    CriticalCVSS 9.1No exploitEPSS 1%

    johnson controls · american dynamics illustra essentials gen 4Jul 2, 2024

  • exacqVision - Key exchanges

    CriticalCVSS 9.0No exploitEPSS 0%

    johnsoncontrols · exacqvision clientAug 1, 2024

  • Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code Execution

    HighCVSS 8.8No exploitEPSS 2%

    johnsoncontrols · frick controls quantum hd firmwareFeb 27, 2026

  • Metasys Improper Privilege Management

    HighCVSS 8.8No exploitEPSS 1%

    johnsoncontrols · metasysJun 4, 2021

  • Metasys privilege management

    HighCVSS 8.8No exploitEPSS 1%

    johnsoncontrols · metasys application and data serverApr 29, 2022

  • Metasys Unverified Password Change

    HighCVSS 8.8No exploitEPSS 1%

    johnsoncontrols · metasys application and data serverMay 6, 2022

  • Successful exploitation of this vulnerability could give an authenticated Facility Explorer SNC Series Supervisory Controller (F4-SNC) user

    HighCVSS 8.8No exploitEPSS 1%

    johnsoncontrols · f4-snc firmwareJul 1, 2021

  • Server-Side Request Forgery (SSRF) vulnerability in Johnson Controls Metasys could allow an authenticated attacker to inject malicious code

    HighCVSS 8.8No exploitEPSS 1%

    johnsoncontrols · metasys application and data serverApr 7, 2022

  • Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code Execution

    HighCVSS 8.8No exploitEPSS 1%

    johnsoncontrols · frick controls quantum hd firmwareFeb 27, 2026