CVE-2019-7594: Metasys use of hardcoded RC2 key
Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a hardcoded RC2 key for certain encryption operations involving the Site Management Portal (SMP).
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2019-7594?
CVE-2019-7594 is a vulnerability that affects Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to version 9.0.
How does CVE-2019-7594 impact the affected software?
CVE-2019-7594 allows an attacker to make use of a hardcoded RC2 key for certain encryption operations involving the Site Management Portal (SMP) in Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to version 9.0.
What is the severity of CVE-2019-7594?
CVE-2019-7594 has a severity rating of 9.1 (critical).
How can I fix the CVE-2019-7594 vulnerability?
To fix the CVE-2019-7594 vulnerability, it is recommended to upgrade the affected software to version 9.0 or higher.
Are there any references for CVE-2019-7594?
Yes, you can find more information about CVE-2019-7594 at the following references: [1] Johnson Controls Product Security Advisory [2] US-CERT ICS Advisory.