Vulnerabilidades en Johnson Controls

82 resultados
Análisis Vexday

Com 76 CVEs catalogadas, o portfólio de vulnerabilidades da Johnson Controls apresenta taxa de exploração ativa abaixo da média geral do catálogo KEV, sem registros confirmados de exploração em andamento. Ainda assim, 11 falhas de severidade crítica merecem atenção prioritária nos ciclos de gestão de patches, especialmente CVE-2020-9047, que concentra o maior escore EPSS observado no conjunto (0,0777) e permanece como a vulnerabilidade de maior risco relativo ativo. A falha mais recorrente por tipo é CWE-79 (Cross-Site Scripting), sugerindo lacunas recorrentes em validação de entrada nas interfaces web dos produtos. A ausência de novas CVEs nos últimos 90 dias e a existência de apenas um PoC público reduzem a superfície de ameaça imediata, mas não eliminam a necessidade de monitoramento contínuo dado o volume crítico acumulado.

CVE-2020-9047MEDIUMexacqVision Software - Improper Verification of Cryptographic SignatureEPSS 7.8%CVE-2020-9050HIGHMetasys Reporting Engine (MRE) Web Services - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')EPSS 2.1%CVE-2021-27660HIGHC-CURE 9000EPSS 2.1%CVE-2022-21941CRITICALiSTAR UltraEPSS 2.0%CVE-2021-27663HIGHCEM Systems AC2000EPSS 1.7%CVE-2019-7589CRITICALKantech EntraPass Improper Input ValidationEPSS 1.6%CVE-2021-27664CRITICALexacqVision Web ServiceEPSS 1.6%CVE-2021-27665HIGHexacqVision Server 32-bitEPSS 1.6%CVE-2026-21654HIGHJohnson Controls -Frick Quantum HD- Unauthenticated Remote Code ExecutionEPSS 1.5%CVE-2025-26385CRITICALMetasys product command injection vulnerability could allow remote SQL executionEPSS 1.4%CVE-2020-9044HIGHMetasys Improper Restriction of XML External Entity ReferenceEPSS 1.3%CVE-2021-27657HIGHMetasys Improper Privilege ManagementEPSS 1.2%CVE-2021-27659MEDIUMexacqVision Web Service CSSEPSS 1.2%CVE-2021-27656MEDIUMexacqVision Web Services - Information ExposureEPSS 1.2%CVE-2020-9048HIGHvictor Web Client - Arbitrary File Deletion VulnerabilityEPSS 1.1%CVE-2023-2024CRITICALImproper Authentication for OpenBlue Enterprise Manager Data CollectorEPSS 1.1%CVE-2021-36198HIGHEntrapassEPSS 1.1%CVE-2021-36199MEDIUMVideoEdgeEPSS 1.0%CVE-2021-36205HIGHMetasys session tokenEPSS 1.0%CVE-2020-9045CRITICALC•CURE 9000 and victor Video Management System - Cleartext storage of user credentials upon installation or upgrade of software.EPSS 1.0%