Vulnerabilidades en Johnson Controls

90 resultados
Análisis Vexday

Com 76 CVEs catalogadas, o portfólio de vulnerabilidades da Johnson Controls apresenta taxa de exploração ativa abaixo da média geral do catálogo KEV, sem registros confirmados de exploração em andamento. Ainda assim, 11 falhas de severidade crítica merecem atenção prioritária nos ciclos de gestão de patches, especialmente CVE-2020-9047, que concentra o maior escore EPSS observado no conjunto (0,0777) e permanece como a vulnerabilidade de maior risco relativo ativo. A falha mais recorrente por tipo é CWE-79 (Cross-Site Scripting), sugerindo lacunas recorrentes em validação de entrada nas interfaces web dos produtos. A ausência de novas CVEs nos últimos 90 dias e a existência de apenas um PoC público reduzem a superfície de ameaça imediata, mas não eliminam a necessidade de monitoramento contínuo dado o volume crítico acumulado.

CVE-2024-32756MEDIUMAmerican Dynamics Illustra Essentials Gen 4 - Reversible User Credential - LinuxEPSS 0.4%CVE-2026-34496HIGHvictor Web - Priviledge EscalationEPSS 0.3%CVE-2025-26381MEDIUMOpenBlue Mobile Web Application configuration issue for optional for OpenBlue Workplace (formerly FM Systems)EPSS 0.3%CVE-2025-43875HIGHiSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, iSTAR Edge G2 - Authenticated web application command injection - getOptionsInfoEPSS 0.3%CVE-2020-9046HIGHKantech EntraPass Security Management Software - System Permissions VulnerabilityEPSS 0.3%CVE-2026-34491MEDIUMImproper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls Metasys 14 and JohnsoEPSS 0.3%CVE-2025-43876HIGHiSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, iSTAR Edge G2 - Authenticated web application command injection - get8021xSettingsEPSS 0.3%CVE-2026-21662MEDIUMFMS Employee Allows Upload of Unrestricted FilesEPSS 0.3%CVE-2026-34492HIGHAirwall - Arbitrary file readEPSS 0.3%CVE-2025-26383MEDIUMThe iSTAR Configuration Utility (ICU) tool leaks memory, which could result in the unintended exposure of unauthorized data from the WindowsEPSS 0.2%CVE-2026-21660MEDIUMJohnson Controls-Frick Quantum HD-Hardcoded Email Credentials Saved as Plaintext in FirmwareEPSS 0.2%CVE-2024-32864MEDIUMexacqVison - HTTPS Session EstablishmentEPSS 0.2%CVE-2024-32754LOWJohnson Controls Kantech KT1, KT2, and KT400 Door Controllers - Exposure of Sensitive InformationEPSS 0.2%CVE-2024-32863MEDIUMexacqVison - CSRF issues with Web ServiceEPSS 0.2%CVE-2025-61739HIGHJohnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG reusing a nonce, key pair in encryptionEPSS 0.2%CVE-2025-26379HIGHJohnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG use of Cryptographically Weak Pseudo-Random Number GeneratorEPSS 0.2%CVE-2025-61738LOWJohnson Controls PowerG and IQPanel cleartext transmission of sensitive informationEPSS 0.2%CVE-2026-27871LOWTL280EPSS 0.2%CVE-2024-0912HIGHCCURE passwords exposed to administratorsEPSS 0.2%CVE-2024-32861HIGHSoftware House C•CURE - CouchDB executable protectionEPSS 0.1%