Vulnerability index

Browse CVEs

70 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Metasys Application And Data Server CRITICAL 9.1
CVE-2020-9044

XXE vulnerability exists in the Metasys family of product Web Services which has the potential to facilitate DoS attacks or harvesting of ASCII serve…

Fix: after 13.2
Fix from $2,300 2020-03-10
Entrapass CRITICAL 9.8
CVE-2019-7589

A vulnerability with the SmartService API Service option exists whereby an unauthorized user could potentially exploit this to upload malicious code …

Fix: 8.10+
Fix from $2,300 2020-03-10
Metasys System CRITICAL 9.1
CVE-2019-7593

Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a shared RSA key pair for certain encryption operations involving the Site …

Fix: 9.0+
Fix from $2,300 2019-08-20
Metasys System CRITICAL 9.1
CVE-2019-7594

Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a hardcoded RC2 key for certain encryption operations involving the Site Ma…

Fix: 9.0+
Fix from $2,300 2019-08-20
Exacqvision Server HIGH 7.8
CVE-2019-7590

ExacqVision Server’s services 'exacqVisionServer', 'dvrdhcpserver' and 'mdnsresponder' have an unquoted service path. If an authenticated user is abl…

Patch available
Fix from $1,950 2019-07-19
Bcpro MEDIUM 6.5
CVE-2018-10624

In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error…

Fix: 3.0.2+
Fix from $1,600 2018-08-01
Metsys HIGH 10.0
CVE-2014-5428

Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Serve…

Mitigation only
Fix from $1,950 2015-03-29
Metsys MEDIUM 5.0
CVE-2014-5427

Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Cont…

Mitigation only
Fix from $1,600 2015-03-29
Pegasys P2000 Server Software MEDIUM 5.0
CVE-2012-4026

The Johnson Controls Pegasys P2000 server with software before 3.11 allows remote attackers to trigger false alerts via crafted packets to TCP port 4…

Fix: after 3.10
Fix from $1,600 2012-07-16
Network Controller HIGH 7.5
CVE-2012-2607

The Johnson Controls CK721-A controller with firmware before SSM4388_03.1.0.14_BB allows remote attackers to perform arbitrary actions via crafted pa…

Fix: after 03.1.0.14
Fix from $1,950 2012-07-16