Vendor CVEs
Johnson Controls
All CVEs
94 total · sorted by risk| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-0242 | Hig | 0.47 | 7.3 | 0.01 | Feb 8, 2024 | Under certain circumstances IQ Panel4 and IQ4 Hub panel software prior to version 4.4.2 could allow unauthorized access to settings. | ||
| CVE-2026-64887 | Hig | 0.46 | — | 0.00 | Aug 14, 2026 | Use of hard-coded cryptographic key vulnerability in Johnson Controls Airwall allows : Cryptanalytic Attack. This issue affects Airwall: before 4.1. | ||
| CVE-2026-34492 | Hig | 0.46 | — | 0.00 | Aug 14, 2026 | External control of file name or path vulnerability in Johnson Controls Airwall allows : File Manipulation. This issue affects Airwall: before 4.1. | ||
| CVE-2026-34496 | Hig | 0.46 | — | 0.00 | Jul 23, 2026 | Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233. This issue affects victor Web: before 7.1. | ||
| CVE-2025-26386 | Hig | 0.46 | — | 0.00 | Jan 28, 2026 | Johnson Controls iSTAR Configuration Utility (ICU) has Stack-based Buffer Overflow vulnerability. This issue affects iSTAR Configuration Utility (ICU) version 6.9.7 and prior. Successful exploitation of this vulnerability could result in failure within the operating system of… | ||
| CVE-2023-3749 | Hig | 0.46 | 7.1 | 0.00 | Aug 3, 2023 | A local user could edit the VideoEdge configuration file and interfere with VideoEdge operation. | ||
| CVE-2020-9049 | Hig | 0.46 | 7.1 | 0.01 | Nov 19, 2020 | A vulnerability in specified versions of American Dynamics victor Web Client and Software House C•CURE Web Client could allow an unauthenticated attacker on the network to create and sign their own JSON Web Token and use it to execute an HTTP API Method without the need for… | ||
| CVE-2020-9048 | Hig | 0.46 | 7.1 | 0.01 | Oct 8, 2020 | A vulnerability in specified versions of American Dynamics victor Web Client and Software House CCURE Web Client could allow a remote unauthenticated attacker on the network to delete arbitrary files on the system or render the system unusable by conducting a Denial of Service… | ||
| CVE-2026-27875 | Med | 0.45 | — | 0.00 | Aug 21, 2026 | Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Controls Simplex Incident Manager / Autocall Fire Administrator may allow an attcker to Retrieve Embedded Sensitive Data. This issue affects Simplex Incident Manager / Autocall Fire Administrator:… | ||
| CVE-2020-9047 | Med | 0.45 | 6.8 | 0.08 | Jun 26, 2020 | A vulnerability exists that could allow the execution of unauthorized code or operating system commands on systems running exacqVision Web Service versions 20.06.3.0 and prior and exacqVision Enterprise Manager versions 20.06.4.0 and prior. An attacker with administrative… | ||
| CVE-2024-32862 | Med | 0.44 | 6.8 | 0.00 | Aug 1, 2024 | Under certain circumstances the ExacqVision Web Services does not provide sufficient protection from untrusted domains. | ||
| CVE-2024-32863 | Med | 0.44 | 6.8 | 0.00 | Aug 1, 2024 | Under certain circumstances the exacqVision Web Services may be susceptible to Cross-Site Request Forgery (CSRF) | ||
| CVE-2024-32932 | Med | 0.44 | 6.8 | 0.00 | Jul 2, 2024 | Under certain circumstances the web interface users credentials may be recovered by an authenticated user. | ||
| CVE-2024-32757 | Med | 0.44 | 6.8 | 0.00 | Jul 2, 2024 | Under certain circumstances unnecessary user details are provided within system logs | ||
| CVE-2024-32756 | Med | 0.44 | 6.8 | 0.00 | Jul 2, 2024 | Under certain circumstances the Linux users credentials may be recovered by an authenticated user. | ||
| CVE-2019-7594 | Med | 0.44 | 6.8 | 0.01 | Aug 20, 2019 | Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a hardcoded RC2 key for certain encryption operations involving the Site Management Portal (SMP). | ||
| CVE-2019-7593 | Med | 0.44 | 6.8 | 0.01 | Aug 20, 2019 | Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a shared RSA key pair for certain encryption operations involving the Site Management Portal (SMP). | ||
| CVE-2019-7590 | Med | 0.44 | 6.7 | 0.01 | Jul 19, 2019 | ExacqVision Server’s services 'exacqVisionServer', 'dvrdhcpserver' and 'mdnsresponder' have an unquoted service path. If an authenticated user is able to insert code in their system root path it potentially can be executed during the application startup. This could allow the… | ||
| CVE-2019-7588 | Med | 0.44 | 6.7 | 0.01 | Jun 18, 2019 | A vulnerability in the exacqVision Enterprise System Manager (ESM) v5.12.2 application whereby unauthorized privilege escalation can potentially be achieved. This vulnerability impacts exacqVision ESM v5.12.2 and all prior versions of ESM running on a Windows operating system.… | ||
| CVE-2024-32865 | Med | 0.42 | 6.4 | 0.00 | Aug 1, 2024 | Under certain circumstances the exacqVision Server will not properly validate TLS certificates provided by connected devices. | ||
| CVE-2024-32864 | Med | 0.42 | 6.4 | 0.00 | Aug 1, 2024 | Under certain circumstances exacqVision Web Services will not enforce secure web communications (HTTPS) | ||
| CVE-2026-34491 | Med | 0.40 | — | 0.00 | Aug 24, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls Metasys 14 and Johnson Controls Metasys 15 allows Cross Site Scripting. This issue affects Metasys 14: before 14.1.5; Metasys 15: before 15.0.1. | ||
| CVE-2024-32931 | Med | 0.37 | 5.7 | 0.00 | Aug 1, 2024 | Under certain circumstances the exacqVision Web Service can expose authentication token details within communications. | ||
| CVE-2026-34490 | Med | 0.36 | 5.5 | 0.00 | Jul 31, 2026 | Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data. This issue affects XAAP Application: before 1.53. | ||
| CVE-2026-34497 | Med | 0.35 | 5.4 | 0.00 | Jul 31, 2026 | Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site Scripting (XSS). This issue affects FM Systems Employee: before 2025.3.1. | ||
| CVE-2026-34495 | Med | 0.35 | 5.4 | 0.00 | Jul 31, 2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Systems Employee allows Stored XSS. This issue affects FM Systems Employee: before 2025.3.1. | ||
| CVE-2021-36203 | Med | 0.35 | 5.3 | 0.01 | Apr 22, 2022 | The affected product may allow an attacker to identify and forge requests to internal systems by way of a specially crafted request. | ||
| CVE-2022-26643 | Med | 0.35 | 5.3 | 0.01 | Apr 13, 2022 | An issue in EasyIO CPT Graphics v0.8 allows attackers to discover valid users in the application. | ||
| CVE-2021-36199 | Med | 0.35 | 5.3 | 0.01 | Jan 14, 2022 | Running a vulnerability scanner against VideoEdge NVRs can cause some functionality to stop. | ||
| CVE-2021-27659 | Med | 0.35 | 5.3 | 0.01 | Jun 24, 2021 | exacqVision Web Service 21.03 does not sufficiently validate, filter, escape, and/or encode user-controllable input before it is placed in output that is used as a web page that is served to other users. | ||
| CVE-2021-27656 | Med | 0.35 | 5.3 | 0.01 | Mar 18, 2021 | A vulnerability in exacqVision Web Service 20.12.2.0 and prior could allow an unauthenticated attacker to view system-level information about the exacqVision Web Service and the operating system. | ||
| CVE-2026-64896 | Med | 0.34 | — | 0.00 | Aug 27, 2026 | Debug and Test Interface With Improper Access Control vulnerability in Johnson Controls T2000 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects T2000: before 31.6. | ||
| CVE-2021-36200 | Med | 0.34 | 5.3 | 0.01 | Jul 22, 2022 | Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.2 and enumerate users. | ||
| CVE-2023-2025 | Med | 0.33 | 5.0 | 0.01 | May 18, 2023 | OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 may expose sensitive information to an unauthorized user under certain circumstances. | ||
| CVE-2021-36201 | Med | 0.28 | 4.3 | 0.01 | Oct 11, 2022 | Under certain circumstances a CCURE Portal user could enumerate user accounts in CCURE 9000 version 2.90 and prior versions. | ||
| CVE-2021-27658 | Med | 0.28 | 4.3 | 0.01 | Jun 24, 2021 | exacqVision Enterprise Manager 20.12 does not sufficiently validate, filter, escape, and/or encode user-controllable input before it is placed in output that is used as a web page that is served to other users. | ||
| CVE-2018-10624 | Med | 0.28 | 4.3 | 0.01 | Aug 1, 2018 | In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could allow an attacker to obtain technical information. | ||
| CVE-2024-0912 | Med | 0.27 | 4.2 | 0.00 | Jun 6, 2024 | Under certain circumstances the Microsoft® Internet Information Server (IIS) used to host the C•CURE 9000 Web Server will log Microsoft Windows credential details within logs. There is no impact to non-web service interfaces C•CURE 9000 or prior versions | ||
| CVE-2024-32754 | Low | 0.20 | 3.1 | 0.00 | Jul 4, 2024 | Under certain circumstances, when the controller is in factory reset mode waiting for initial setup, it will broadcast its MAC address, serial number, and firmware version. Once configured, the controller will no longer broadcast this information. | ||
| CVE-2025-61738 | Low | 0.15 | — | 0.00 | Dec 22, 2025 | Under certain circumstances, attacker can capture the network key, read or write encrypted packets on the PowerG network. | ||
| CVE-2014-5428 | 0.00 | — | 0.04 | Mar 29, 2015 | Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE)… | |||
| CVE-2014-5427 | 0.00 | — | 0.01 | Mar 29, 2015 | Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote… | |||
| CVE-2012-4026 | 0.00 | — | 0.01 | Jul 16, 2012 | The Johnson Controls Pegasys P2000 server with software before 3.11 allows remote attackers to trigger false alerts via crafted packets to TCP port 41013 (aka the upload port), a different vulnerability than CVE-2012-2607. | |||
| CVE-2012-2607 | 0.00 | — | 0.02 | Jul 16, 2012 | The Johnson Controls CK721-A controller with firmware before SSM4388_03.1.0.14_BB allows remote attackers to perform arbitrary actions via crafted packets to TCP port 41014 (aka the download port). |
- risk 0.47cvss 7.3epss 0.01
Under certain circumstances IQ Panel4 and IQ4 Hub panel software prior to version 4.4.2 could allow unauthorized access to settings.
- risk 0.46cvss —epss 0.00
Use of hard-coded cryptographic key vulnerability in Johnson Controls Airwall allows : Cryptanalytic Attack. This issue affects Airwall: before 4.1.
- risk 0.46cvss —epss 0.00
External control of file name or path vulnerability in Johnson Controls Airwall allows : File Manipulation. This issue affects Airwall: before 4.1.
- risk 0.46cvss —epss 0.00
Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233. This issue affects victor Web: before 7.1.
- risk 0.46cvss —epss 0.00
Johnson Controls iSTAR Configuration Utility (ICU) has Stack-based Buffer Overflow vulnerability. This issue affects iSTAR Configuration Utility (ICU) version 6.9.7 and prior. Successful exploitation of this vulnerability could result in failure within the operating system of…
- risk 0.46cvss 7.1epss 0.00
A local user could edit the VideoEdge configuration file and interfere with VideoEdge operation.
- risk 0.46cvss 7.1epss 0.01
A vulnerability in specified versions of American Dynamics victor Web Client and Software House C•CURE Web Client could allow an unauthenticated attacker on the network to create and sign their own JSON Web Token and use it to execute an HTTP API Method without the need for…
- risk 0.46cvss 7.1epss 0.01
A vulnerability in specified versions of American Dynamics victor Web Client and Software House CCURE Web Client could allow a remote unauthenticated attacker on the network to delete arbitrary files on the system or render the system unusable by conducting a Denial of Service…
- risk 0.45cvss —epss 0.00
Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Controls Simplex Incident Manager / Autocall Fire Administrator may allow an attcker to Retrieve Embedded Sensitive Data. This issue affects Simplex Incident Manager / Autocall Fire Administrator:…
- risk 0.45cvss 6.8epss 0.08
A vulnerability exists that could allow the execution of unauthorized code or operating system commands on systems running exacqVision Web Service versions 20.06.3.0 and prior and exacqVision Enterprise Manager versions 20.06.4.0 and prior. An attacker with administrative…
- risk 0.44cvss 6.8epss 0.00
Under certain circumstances the ExacqVision Web Services does not provide sufficient protection from untrusted domains.
- risk 0.44cvss 6.8epss 0.00
Under certain circumstances the exacqVision Web Services may be susceptible to Cross-Site Request Forgery (CSRF)
- risk 0.44cvss 6.8epss 0.00
Under certain circumstances the web interface users credentials may be recovered by an authenticated user.
- risk 0.44cvss 6.8epss 0.00
Under certain circumstances unnecessary user details are provided within system logs
- risk 0.44cvss 6.8epss 0.00
Under certain circumstances the Linux users credentials may be recovered by an authenticated user.
- risk 0.44cvss 6.8epss 0.01
Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a hardcoded RC2 key for certain encryption operations involving the Site Management Portal (SMP).
- risk 0.44cvss 6.8epss 0.01
Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a shared RSA key pair for certain encryption operations involving the Site Management Portal (SMP).
- risk 0.44cvss 6.7epss 0.01
ExacqVision Server’s services 'exacqVisionServer', 'dvrdhcpserver' and 'mdnsresponder' have an unquoted service path. If an authenticated user is able to insert code in their system root path it potentially can be executed during the application startup. This could allow the…
- risk 0.44cvss 6.7epss 0.01
A vulnerability in the exacqVision Enterprise System Manager (ESM) v5.12.2 application whereby unauthorized privilege escalation can potentially be achieved. This vulnerability impacts exacqVision ESM v5.12.2 and all prior versions of ESM running on a Windows operating system.…
- risk 0.42cvss 6.4epss 0.00
Under certain circumstances the exacqVision Server will not properly validate TLS certificates provided by connected devices.
- risk 0.42cvss 6.4epss 0.00
Under certain circumstances exacqVision Web Services will not enforce secure web communications (HTTPS)
- risk 0.40cvss —epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls Metasys 14 and Johnson Controls Metasys 15 allows Cross Site Scripting. This issue affects Metasys 14: before 14.1.5; Metasys 15: before 15.0.1.
- risk 0.37cvss 5.7epss 0.00
Under certain circumstances the exacqVision Web Service can expose authentication token details within communications.
- risk 0.36cvss 5.5epss 0.00
Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data. This issue affects XAAP Application: before 1.53.
- risk 0.35cvss 5.4epss 0.00
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site Scripting (XSS). This issue affects FM Systems Employee: before 2025.3.1.
- risk 0.35cvss 5.4epss 0.00
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Systems Employee allows Stored XSS. This issue affects FM Systems Employee: before 2025.3.1.
- risk 0.35cvss 5.3epss 0.01
The affected product may allow an attacker to identify and forge requests to internal systems by way of a specially crafted request.
- risk 0.35cvss 5.3epss 0.01
An issue in EasyIO CPT Graphics v0.8 allows attackers to discover valid users in the application.
- risk 0.35cvss 5.3epss 0.01
Running a vulnerability scanner against VideoEdge NVRs can cause some functionality to stop.
- risk 0.35cvss 5.3epss 0.01
exacqVision Web Service 21.03 does not sufficiently validate, filter, escape, and/or encode user-controllable input before it is placed in output that is used as a web page that is served to other users.
- risk 0.35cvss 5.3epss 0.01
A vulnerability in exacqVision Web Service 20.12.2.0 and prior could allow an unauthenticated attacker to view system-level information about the exacqVision Web Service and the operating system.
- risk 0.34cvss —epss 0.00
Debug and Test Interface With Improper Access Control vulnerability in Johnson Controls T2000 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects T2000: before 31.6.
- risk 0.34cvss 5.3epss 0.01
Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.2 and enumerate users.
- risk 0.33cvss 5.0epss 0.01
OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 may expose sensitive information to an unauthorized user under certain circumstances.
- risk 0.28cvss 4.3epss 0.01
Under certain circumstances a CCURE Portal user could enumerate user accounts in CCURE 9000 version 2.90 and prior versions.
- risk 0.28cvss 4.3epss 0.01
exacqVision Enterprise Manager 20.12 does not sufficiently validate, filter, escape, and/or encode user-controllable input before it is placed in output that is used as a web page that is served to other users.
- risk 0.28cvss 4.3epss 0.01
In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could allow an attacker to obtain technical information.
- risk 0.27cvss 4.2epss 0.00
Under certain circumstances the Microsoft® Internet Information Server (IIS) used to host the C•CURE 9000 Web Server will log Microsoft Windows credential details within logs. There is no impact to non-web service interfaces C•CURE 9000 or prior versions
- risk 0.20cvss 3.1epss 0.00
Under certain circumstances, when the controller is in factory reset mode waiting for initial setup, it will broadcast its MAC address, serial number, and firmware version. Once configured, the controller will no longer broadcast this information.
- risk 0.15cvss —epss 0.00
Under certain circumstances, attacker can capture the network key, read or write encrypted packets on the PowerG network.
- CVE-2014-5428Mar 29, 2015risk 0.00cvss —epss 0.04
Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE)…
- CVE-2014-5427Mar 29, 2015risk 0.00cvss —epss 0.01
Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote…
- CVE-2012-4026Jul 16, 2012risk 0.00cvss —epss 0.01
The Johnson Controls Pegasys P2000 server with software before 3.11 allows remote attackers to trigger false alerts via crafted packets to TCP port 41013 (aka the upload port), a different vulnerability than CVE-2012-2607.
- CVE-2012-2607Jul 16, 2012risk 0.00cvss —epss 0.02
The Johnson Controls CK721-A controller with firmware before SSM4388_03.1.0.14_BB allows remote attackers to perform arbitrary actions via crafted packets to TCP port 41014 (aka the download port).
Page 2 of 2