Vulnerabilities (CVE)

Filtered by vendor Johnsoncontrols Subscribe
Filtered by product Metasys System
Total 3 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-10624 1 Johnsoncontrols 2 Bcpro, Metasys System 2024-01-23 3.3 LOW 6.5 MEDIUM
In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could allow an attacker to obtain technical information.
CVE-2019-7594 1 Johnsoncontrols 1 Metasys System 2023-12-10 6.4 MEDIUM 9.1 CRITICAL
Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a hardcoded RC2 key for certain encryption operations involving the Site Management Portal (SMP).
CVE-2019-7593 1 Johnsoncontrols 1 Metasys System 2023-12-10 6.4 MEDIUM 9.1 CRITICAL
Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a shared RSA key pair for certain encryption operations involving the Site Management Portal (SMP).