First published: Tue Aug 20 2019(Updated: )
Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a shared RSA key pair for certain encryption operations involving the Site Management Portal (SMP).
Credit: productsecurity@jci.com
Affected Software | Affected Version | How to fix |
---|---|---|
Johnsoncontrols Metasys System | <9.0 |
Upgrade Metasys® devices to Release 9.0 or later and configure sites with trusted certificates.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7593 is a vulnerability in Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 that make use of a shared RSA key pair for certain encryption operations involving the Site Management Portal (SMP).
CVE-2019-7593 has a severity value of 9.1, which is classified as critical.
Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to version 9.0 are affected by CVE-2019-7593.
CVE-2019-7593 is associated with CWE-798 (Use of Hard-coded Credentials) and CWE-323 (Reusing a Nonce, Key Pair in Encryption)
You can find more information about CVE-2019-7593 in the following references: [1] [2]