Vulnerabilities (CVE)

Filtered by vendor Johnsoncontrols Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-0248 1 Johnsoncontrols 2 Iosmart Gen 1, Iosmart Gen 1 Firmware 2023-12-21 N/A 5.3 MEDIUM
An attacker with physical access to the Kantech Gen1 ioSmart card reader with firmware version prior to 1.07.02 in certain circumstances can recover the reader's communication memory between the card and reader.
CVE-2023-3749 1 Johnsoncontrols 1 Videoedge 2023-08-09 N/A 5.5 MEDIUM
A local user could edit the VideoEdge configuration file and interfere with VideoEdge operation.
CVE-2021-36200 1 Johnsoncontrols 3 Metasys Application And Data Server, Metasys Extended Application And Data Server, Metasys Open Application Server 2022-07-29 N/A 5.3 MEDIUM
Under certain circumstances an unauthenticated user could access the the web API for Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.2 and enumerate users.
CVE-2022-21938 1 Johnsoncontrols 3 Metasys Application And Data Server, Metasys Extended Application And Data Server, Metasys Open Application Server 2022-06-24 3.5 LOW 5.4 MEDIUM
Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 could allow a user to inject malicious code into the MUI Graphics web interface.
CVE-2022-21937 1 Johnsoncontrols 3 Metasys Application And Data Server, Metasys Extended Application And Data Server, Metasys Open Application Server 2022-06-24 2.1 LOW 5.4 MEDIUM
Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 could allow a user to inject malicious code into the web interface.
CVE-2021-36199 1 Johnsoncontrols 1 Videoedge 2022-01-21 5.0 MEDIUM 5.3 MEDIUM
Running a vulnerability scanner against VideoEdge NVRs can cause some functionality to stop.
CVE-2021-27659 1 Johnsoncontrols 1 Exacqvision Web Service 2021-09-20 4.3 MEDIUM 6.1 MEDIUM
exacqVision Web Service 21.03 does not sufficiently validate, filter, escape, and/or encode user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVE-2021-27658 1 Johnsoncontrols 1 Exacqvision Enterprise Manager 2021-09-20 3.5 LOW 5.4 MEDIUM
exacqVision Enterprise Manager 20.12 does not sufficiently validate, filter, escape, and/or encode user-controllable input before it is placed in output that is used as a web page that is served to other users.
CVE-2020-9045 2 Johnsoncontrols, Tyco 2 C-cure 9000 Firmware, Victor Video Management System 2021-07-06 4.0 MEDIUM 6.5 MEDIUM
During installation or upgrade to Software House C•CURE 9000 v2.70 and American Dynamics victor Video Management System v5.2, the credentials of the user used to perform the installation or upgrade are logged in a file. The install log file persists after the installation.
CVE-2020-9049 1 Johnsoncontrols 2 C-cure Web, Victor Web 2020-12-04 5.7 MEDIUM 5.3 MEDIUM
A vulnerability in specified versions of American Dynamics victor Web Client and Software House C•CURE Web Client could allow an unauthenticated attacker on the network to create and sign their own JSON Web Token and use it to execute an HTTP API Method without the need for valid authentication/authorization. Under certain circumstances, this could be used by an attacker to impact system availability by conducting a Denial of Service attack.
CVE-2018-10624 1 Johnsoncontrols 2 Bcpro, Metasys System 2019-10-09 3.3 LOW 6.5 MEDIUM
In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could allow an attacker to obtain technical information.