johnsoncontrols records
80 published records for vendor johnsoncontrols.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 8
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')6
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor5
- CWE-269 Improper Privilege Management4
- CWE-20 Improper Input Validation4
- CWE-94 Improper Control of Generation of Code ('Code Injection')3
- CWE-287 Improper Authentication3
The weakness classes this vendor ships most often: where to look.
CWEAll records
80 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
41Plan | CVE-2014-5428No exploit | Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used in Application and Djohnsoncontrols · metsys | Critical10.0 | — | 3.9% | Mar 29, 2015 |
40Plan | CVE-2022-21941No exploit | All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauthenticated user root johnsoncontrols · istar ultra firmware · CWE-77 | Critical9.8 | — | 2.1% | Aug 31, 2022 |
40Plan | CVE-2021-27663No exploit | A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems AC2000 allows a remote attacker to access to the system withoujohnsoncontrols · ac2000 firmware · CWE-285 | Critical9.8 | — | 1.7% | Aug 30, 2021 |
39Monitor | CVE-2019-7589No exploit | Kantech EntraPass Improper Input Validationjohnsoncontrols · entrapass · CWE-20 | Critical9.8 | — | 1.6% | Mar 10, 2020 |
39Monitor | CVE-2021-27664No exploit | exacqVision Web Servicejohnsoncontrols · exacqvision web service · CWE-269 | Critical9.8 | — | 1.6% | Oct 11, 2021 |
39Monitor | CVE-2021-36205No exploit | Metasys session tokenjohnsoncontrols · metasys application and data server · CWE-459 | Critical9.8 | — | 1.0% | Apr 15, 2022 |
39Monitor | CVE-2023-4804No exploit | An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.johnsoncontrols · quantum hd unity compressor firmware · CWE-489 | Critical9.8 | — | 0.8% | Nov 10, 2023 |
39Monitor | CVE-2023-0954No exploit | Debug feature in Sensormatic Electronics Illustra Dome and PTZ camerasjohnsoncontrols · illustra pro gen 4 dome firmware · CWE-489 | Critical9.8 | — | 0.7% | Jun 8, 2023 |
39Monitor | CVE-2024-0242No exploit | Unauthorized access to settings in Qolsys IQ Panel 4 and IQ4 Hubjohnsoncontrols · qolsys iq panel 4 firmware · CWE-200 | Critical9.8 | — | 0.6% | Feb 8, 2024 |
39Monitor | CVE-2023-3127No exploit | Improper Authentication in iSTARjohnsoncontrols · istar ultra firmware · CWE-287 | Critical9.8 | — | 0.6% | Jul 11, 2023 |
39Monitor | CVE-2023-3548No exploit | An unauthorized user could gain account access to IQ Wifi 6 versions prior to 2.0.2 by conducting a brute force authentication attack.johnsoncontrols · iq wifi 6 firmware · CWE-307 | Critical9.8 | — | 0.6% | Jul 25, 2023 |
36Monitor | CVE-2021-27660No exploit | An insecure client auto update feature in C-CURE 9000 can allow remote execution of lower privileged Windows programs.johnsoncontrols · c-cure 9000 firmware · CWE-20 | High8.8 | — | 2.1% | Jul 1, 2021 |
36Monitor | CVE-2020-9044No exploit | Metasys Improper Restriction of XML External Entity Referencejohnsoncontrols · metasys application and data server · CWE-611 | Critical9.1 | — | 1.3% | Mar 10, 2020 |
36Monitor | CVE-2021-36203No exploit | Johnson Controls Metasys SCT Projohnsoncontrols · metasys system configuration tool · CWE-918 | Critical9.1 | — | 0.9% | Apr 22, 2022 |
36Monitor | CVE-2019-7593No exploit | Metasys use of shared RSA key pairsjohnsoncontrols · metasys system · CWE-323 | Critical9.1 | — | 0.8% | Aug 20, 2019 |
36Monitor | CVE-2019-7594No exploit | Metasys use of hardcoded RC2 keyjohnsoncontrols · metasys system · CWE-321 | Critical9.1 | — | 0.6% | Aug 20, 2019 |
36Monitor | CVE-2024-32755No exploit | American Dynamics Illustra Essentials Gen 4 - Log Filter Input Validationjohnson controls · american dynamics illustra essentials gen 4 · CWE-20 | Critical9.1 | — | 0.5% | Jul 2, 2024 |
36Monitor | CVE-2024-32758No exploit | exacqVision - Key exchangesjohnsoncontrols · exacqvision client · CWE-326 | Critical9.0 | — | 0.4% | Aug 1, 2024 |
35Monitor | CVE-2026-21654No exploit | Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code Executionjohnsoncontrols · frick controls quantum hd firmware · CWE-78 | High8.8 | — | 1.5% | Feb 27, 2026 |
35Monitor | CVE-2021-27657No exploit | Metasys Improper Privilege Managementjohnsoncontrols · metasys · CWE-269 | High8.8 | — | 1.2% | Jun 4, 2021 |
35Monitor | CVE-2021-36207No exploit | Metasys privilege managementjohnsoncontrols · metasys application and data server · CWE-269 | High8.8 | — | 1.0% | Apr 29, 2022 |
35Monitor | CVE-2022-21934No exploit | Metasys Unverified Password Changejohnsoncontrols · metasys application and data server · CWE-620 | High8.8 | — | 1.0% | May 6, 2022 |
35Monitor | CVE-2021-27661No exploit | Successful exploitation of this vulnerability could give an authenticated Facility Explorer SNC Series Supervisory Controller (F4-SNC) user johnsoncontrols · f4-snc firmware · CWE-269 | High8.8 | — | 0.8% | Jul 1, 2021 |
35Monitor | CVE-2021-36202No exploit | Server-Side Request Forgery (SSRF) vulnerability in Johnson Controls Metasys could allow an authenticated attacker to inject malicious code johnsoncontrols · metasys application and data server · CWE-918 | High8.8 | — | 0.8% | Apr 7, 2022 |
35Monitor | CVE-2026-21658No exploit | Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code Executionjohnsoncontrols · frick controls quantum hd firmware · CWE-94 | High8.8 | — | 0.6% | Feb 27, 2026 |
- CVE-2014-542841Plan
Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used in Application and D
CriticalCVSS 10.0No exploitEPSS 4%johnsoncontrols · metsysMar 29, 2015
- CVE-2022-2194140Plan
All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauthenticated user root
CriticalCVSS 9.8No exploitEPSS 2%johnsoncontrols · istar ultra firmwareAug 31, 2022
- CVE-2021-2766340Plan
A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems AC2000 allows a remote attacker to access to the system withou
CriticalCVSS 9.8No exploitEPSS 2%johnsoncontrols · ac2000 firmwareAug 30, 2021
- CVE-2019-758939Monitor
Kantech EntraPass Improper Input Validation
CriticalCVSS 9.8No exploitEPSS 2%johnsoncontrols · entrapassMar 10, 2020
- CVE-2021-2766439Monitor
exacqVision Web Service
CriticalCVSS 9.8No exploitEPSS 2%johnsoncontrols · exacqvision web serviceOct 11, 2021
- CVE-2021-3620539Monitor
Metasys session token
CriticalCVSS 9.8No exploitEPSS 1%johnsoncontrols · metasys application and data serverApr 15, 2022
- CVE-2023-480439Monitor
An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.
CriticalCVSS 9.8No exploitEPSS 1%johnsoncontrols · quantum hd unity compressor firmwareNov 10, 2023
- CVE-2023-095439Monitor
Debug feature in Sensormatic Electronics Illustra Dome and PTZ cameras
CriticalCVSS 9.8No exploitEPSS 1%johnsoncontrols · illustra pro gen 4 dome firmwareJun 8, 2023
- CVE-2024-024239Monitor
Unauthorized access to settings in Qolsys IQ Panel 4 and IQ4 Hub
CriticalCVSS 9.8No exploitEPSS 1%johnsoncontrols · qolsys iq panel 4 firmwareFeb 8, 2024
- CVE-2023-312739Monitor
Improper Authentication in iSTAR
CriticalCVSS 9.8No exploitEPSS 1%johnsoncontrols · istar ultra firmwareJul 11, 2023
- CVE-2023-354839Monitor
An unauthorized user could gain account access to IQ Wifi 6 versions prior to 2.0.2 by conducting a brute force authentication attack.
CriticalCVSS 9.8No exploitEPSS 1%johnsoncontrols · iq wifi 6 firmwareJul 25, 2023
- CVE-2021-2766036Monitor
An insecure client auto update feature in C-CURE 9000 can allow remote execution of lower privileged Windows programs.
HighCVSS 8.8No exploitEPSS 2%johnsoncontrols · c-cure 9000 firmwareJul 1, 2021
- CVE-2020-904436Monitor
Metasys Improper Restriction of XML External Entity Reference
CriticalCVSS 9.1No exploitEPSS 1%johnsoncontrols · metasys application and data serverMar 10, 2020
- CVE-2021-3620336Monitor
Johnson Controls Metasys SCT Pro
CriticalCVSS 9.1No exploitEPSS 1%johnsoncontrols · metasys system configuration toolApr 22, 2022
- CVE-2019-759336Monitor
Metasys use of shared RSA key pairs
CriticalCVSS 9.1No exploitEPSS 1%johnsoncontrols · metasys systemAug 20, 2019
- CVE-2019-759436Monitor
Metasys use of hardcoded RC2 key
CriticalCVSS 9.1No exploitEPSS 1%johnsoncontrols · metasys systemAug 20, 2019
- CVE-2024-3275536Monitor
American Dynamics Illustra Essentials Gen 4 - Log Filter Input Validation
CriticalCVSS 9.1No exploitEPSS 1%johnson controls · american dynamics illustra essentials gen 4Jul 2, 2024
- CVE-2024-3275836Monitor
exacqVision - Key exchanges
CriticalCVSS 9.0No exploitEPSS 0%johnsoncontrols · exacqvision clientAug 1, 2024
- CVE-2026-2165435Monitor
Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code Execution
HighCVSS 8.8No exploitEPSS 2%johnsoncontrols · frick controls quantum hd firmwareFeb 27, 2026
- CVE-2021-2765735Monitor
Metasys Improper Privilege Management
HighCVSS 8.8No exploitEPSS 1%johnsoncontrols · metasysJun 4, 2021
- CVE-2021-3620735Monitor
Metasys privilege management
HighCVSS 8.8No exploitEPSS 1%johnsoncontrols · metasys application and data serverApr 29, 2022
- CVE-2022-2193435Monitor
Metasys Unverified Password Change
HighCVSS 8.8No exploitEPSS 1%johnsoncontrols · metasys application and data serverMay 6, 2022
- CVE-2021-2766135Monitor
Successful exploitation of this vulnerability could give an authenticated Facility Explorer SNC Series Supervisory Controller (F4-SNC) user
HighCVSS 8.8No exploitEPSS 1%johnsoncontrols · f4-snc firmwareJul 1, 2021
- CVE-2021-3620235Monitor
Server-Side Request Forgery (SSRF) vulnerability in Johnson Controls Metasys could allow an authenticated attacker to inject malicious code
HighCVSS 8.8No exploitEPSS 1%johnsoncontrols · metasys application and data serverApr 7, 2022
- CVE-2026-2165835Monitor
Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code Execution
HighCVSS 8.8No exploitEPSS 1%johnsoncontrols · frick controls quantum hd firmwareFeb 27, 2026