Vulnerabilidades en Johnson Controls

90 resultados
Análisis Vexday

Com 76 CVEs catalogadas, o portfólio de vulnerabilidades da Johnson Controls apresenta taxa de exploração ativa abaixo da média geral do catálogo KEV, sem registros confirmados de exploração em andamento. Ainda assim, 11 falhas de severidade crítica merecem atenção prioritária nos ciclos de gestão de patches, especialmente CVE-2020-9047, que concentra o maior escore EPSS observado no conjunto (0,0777) e permanece como a vulnerabilidade de maior risco relativo ativo. A falha mais recorrente por tipo é CWE-79 (Cross-Site Scripting), sugerindo lacunas recorrentes em validação de entrada nas interfaces web dos produtos. A ausência de novas CVEs nos últimos 90 dias e a existência de apenas um PoC público reduzem a superfície de ameaça imediata, mas não eliminam a necessidade de monitoramento contínuo dado o volume crítico acumulado.

CVE-2022-21939HIGHSensitive cookie without 'HttpOnly' flag in System Configuration Tool (SCT)EPSS 0.5%CVE-2020-9049HIGHvictor Web Client and C•CURE Web Client JSON Web Token (JWT) VulnerabilityEPSS 0.5%CVE-2022-21938HIGHMetasys MUI Graphics XSSEPSS 0.5%CVE-2023-2025MEDIUMExposure of Sensitive Information in OpenBlue Enterprise Manager Data CollectorEPSS 0.5%CVE-2024-32755CRITICALAmerican Dynamics Illustra Essentials Gen 4 - Log Filter Input ValidationEPSS 0.5%CVE-2026-21655HIGHC-CURE 9000 and Victor application server - Deserialization of Untrusted DataEPSS 0.5%CVE-2021-36206CRITICALCEVASEPSS 0.4%CVE-2024-32758CRITICALexacqVision - Key exchangesEPSS 0.4%CVE-2024-32862MEDIUMexacqVision CORSEPSS 0.4%CVE-2024-32759HIGHJohnson Controls Software House C●CURE 9000 installer password strengthEPSS 0.4%CVE-2021-36204HIGHInsufficiently Protected Credentials in Metasys EPSS 0.4%CVE-2025-26386HIGHStack-based Buffer Overflow in Johnson Controls iSTAR Configuration Utility (ICU) toolEPSS 0.4%CVE-2024-32753HIGHTYCO Illustra Pro Gen 4 - JQuery versionEPSS 0.4%CVE-2026-21656HIGHJohnson Controls -Frick Quantum HD- Unauthenticated Remote Code ExecutionEPSS 0.4%CVE-2026-21657HIGHJohnson Controls -Frick Quantum HD- Unauthenticated Remote Code ExecutionEPSS 0.4%CVE-2026-21653HIGHCCure and Victor Application Server - Server Side Request ForgeryEPSS 0.4%CVE-2024-32932MEDIUMAmerican Dynamics Illustra Essentials Gen 4 - Reversible User Credential - stored web interfaceEPSS 0.4%CVE-2024-32931MEDIUMexacqVison - Token Disclosed in URLEPSS 0.4%CVE-2024-32757MEDIUMAmerican Dynamics Illustra Essentials Gen 4 - Linux Credential LeakEPSS 0.4%CVE-2022-21940HIGHSensitive Cookie in HTTPS Session Without 'Secure' Attribute in System Configuration Tool (SCT)EPSS 0.4%