First published: Tue Aug 20 2019(Updated: )
Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a hardcoded RC2 key for certain encryption operations involving the Site Management Portal (SMP).
Credit: productsecurity@jci.com
Affected Software | Affected Version | How to fix |
---|---|---|
Johnsoncontrols Metasys System | <9.0 |
Upgrade Metasys® devices to Release 9.0 or later and configure sites with trusted certificates.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-7594 is a vulnerability that affects Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to version 9.0.
CVE-2019-7594 allows an attacker to make use of a hardcoded RC2 key for certain encryption operations involving the Site Management Portal (SMP) in Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to version 9.0.
CVE-2019-7594 has a severity rating of 9.1 (critical).
To fix the CVE-2019-7594 vulnerability, it is recommended to upgrade the affected software to version 9.0 or higher.
Yes, you can find more information about CVE-2019-7594 at the following references: [1] Johnson Controls Product Security Advisory [2] US-CERT ICS Advisory.