VYPR

Vendor CVEs

Johnson Controls

All CVEs

77 total · sorted by risk
  • CVE-2024-32862MedAug 1, 2024
    risk 0.44cvss 6.8epss 0.00

    Under certain circumstances the ExacqVision Web Services does not provide sufficient protection from untrusted domains.

  • CVE-2024-32863MedAug 1, 2024
    risk 0.44cvss 6.8epss 0.00

    Under certain circumstances the exacqVision Web Services may be susceptible to Cross-Site Request Forgery (CSRF)

  • CVE-2024-32932MedJul 2, 2024
    risk 0.44cvss 6.8epss 0.00

    Under certain circumstances the web interface users credentials may be recovered by an authenticated user.

  • CVE-2024-32757MedJul 2, 2024
    risk 0.44cvss 6.8epss 0.00

    Under certain circumstances unnecessary user details are provided within system logs

  • CVE-2024-32756MedJul 2, 2024
    risk 0.44cvss 6.8epss 0.00

    Under certain circumstances the Linux users credentials may be recovered by an authenticated user.

  • CVE-2019-7594MedAug 20, 2019
    risk 0.44cvss 6.8epss 0.01

    Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a hardcoded RC2 key for certain encryption operations involving the Site Management Portal (SMP).

  • CVE-2019-7593MedAug 20, 2019
    risk 0.44cvss 6.8epss 0.01

    Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a shared RSA key pair for certain encryption operations involving the Site Management Portal (SMP).

  • CVE-2024-32865MedAug 1, 2024
    risk 0.42cvss 6.4epss 0.00

    Under certain circumstances the exacqVision Server will not properly validate TLS certificates provided by connected devices.

  • CVE-2024-32864MedAug 1, 2024
    risk 0.42cvss 6.4epss 0.00

    Under certain circumstances exacqVision Web Services will not enforce secure web communications (HTTPS)

  • CVE-2018-10624MedAug 1, 2018
    risk 0.42cvss 6.5epss 0.01

    In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could allow an attacker to obtain technical information.

  • CVE-2024-32931MedAug 1, 2024
    risk 0.37cvss 5.7epss 0.00

    Under certain circumstances the exacqVision Web Service can expose authentication token details within communications.

  • CVE-2026-34490MedJul 31, 2026
    risk 0.36cvss 5.5epss 0.00

    Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data. This issue affects XAAP Application: before 1.53.

  • CVE-2026-34497MedJul 31, 2026
    risk 0.35cvss 5.4epss 0.00

    Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site Scripting (XSS). This issue affects FM Systems Employee: before 2025.3.1.

  • CVE-2026-34495MedJul 31, 2026
    risk 0.35cvss 5.4epss 0.00

    Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Systems Employee allows Stored XSS. This issue affects FM Systems Employee: before 2025.3.1.

  • CVE-2021-36199MedJan 14, 2022
    risk 0.35cvss 5.3epss 0.01

    Running a vulnerability scanner against VideoEdge NVRs can cause some functionality to stop.

  • CVE-2021-27656MedMar 18, 2021
    risk 0.35cvss 5.3epss 0.01

    A vulnerability in exacqVision Web Service 20.12.2.0 and prior could allow an unauthenticated attacker to view system-level information about the exacqVision Web Service and the operating system.

  • CVE-2021-36200MedJul 22, 2022
    risk 0.34cvss 5.3epss 0.01

    Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.2 and enumerate users.

  • CVE-2023-2025MedMay 18, 2023
    risk 0.33cvss 5.0epss 0.01

    OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 may expose sensitive information to an unauthorized user under certain circumstances.

  • CVE-2021-36201MedOct 11, 2022
    risk 0.28cvss 4.3epss 0.01

    Under certain circumstances a CCURE Portal user could enumerate user accounts in CCURE 9000 version 2.90 and prior versions.

  • CVE-2021-27658MedJun 24, 2021
    risk 0.28cvss 4.3epss 0.01

    exacqVision Enterprise Manager 20.12 does not sufficiently validate, filter, escape, and/or encode user-controllable input before it is placed in output that is used as a web page that is served to other users.

  • CVE-2024-0912MedJun 6, 2024
    risk 0.27cvss 4.2epss 0.00

    Under certain circumstances the Microsoft® Internet Information Server (IIS) used to host the C•CURE 9000 Web Server will log Microsoft Windows credential details within logs. There is no impact to non-web service interfaces C•CURE 9000 or prior versions

  • CVE-2024-32754LowJul 4, 2024
    risk 0.20cvss 3.1epss 0.00

    Under certain circumstances, when the controller is in factory reset mode waiting for initial setup, it will broadcast its MAC address, serial number, and firmware version. Once configured, the controller will no longer broadcast this information.

  • CVE-2025-61738LowDec 22, 2025
    risk 0.15cvss epss 0.00

    Under certain circumstances, attacker can capture the network key, read or write encrypted packets on the PowerG network.

  • CVE-2014-5428Mar 29, 2015
    risk 0.00cvss epss 0.04

    Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE)…

  • CVE-2014-5427Mar 29, 2015
    risk 0.00cvss epss 0.01

    Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote…

  • CVE-2012-4026Jul 16, 2012
    risk 0.00cvss epss 0.01

    The Johnson Controls Pegasys P2000 server with software before 3.11 allows remote attackers to trigger false alerts via crafted packets to TCP port 41013 (aka the upload port), a different vulnerability than CVE-2012-2607.

  • CVE-2012-2607Jul 16, 2012
    risk 0.00cvss epss 0.02

    The Johnson Controls CK721-A controller with firmware before SSM4388_03.1.0.14_BB allows remote attackers to perform arbitrary actions via crafted packets to TCP port 41014 (aka the download port).

Page 2 of 2