First published: Wed Jun 15 2022(Updated: )
Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 could allow a user to inject malicious code into the web interface.
Credit: productsecurity@jci.com
Affected Software | Affected Version | How to fix |
---|---|---|
Johnsoncontrols Metasys Application And Data Server | >=10.0<=10.1.5 | |
Johnsoncontrols Metasys Application And Data Server | =11.0 | |
Johnsoncontrols Metasys Application And Data Server | =11.0.1 | |
Johnsoncontrols Metasys Extended Application And Data Server | >=10.0<=10.1.5 | |
Johnsoncontrols Metasys Extended Application And Data Server | =11.0 | |
Johnsoncontrols Metasys Extended Application And Data Server | =11.0.1 | |
Johnsoncontrols Metasys Open Application Server | >=10.0<10.1.5 | |
Johnsoncontrols Metasys Open Application Server | =11.0 | |
Johnsoncontrols Metasys Open Application Server | =11.0.1 | |
Johnson Controls, Inc. All Metasys ADS/ADX/OAS Versions 10 and 11 |
Update all Metasys ADS/ADX/OAS 10 versions with patch 10.1.5.
Update all Metasys ADS/ADX/OAS 11 versions with patch 11.0.2.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Metasys vulnerability is CVE-2022-21937.
The severity of CVE-2022-21937 is high with a CVSS score of 5.4.
Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 are affected by CVE-2022-21937.
Under certain circumstances, a user can inject malicious code into the web interface of Metasys ADS/ADX/OAS versions prior to 10.1.5 and 11.0.2.
You can find more information about CVE-2022-21937 on the following websites: [CISA.gov](https://www.cisa.gov/uscert/ics/advisories/icsa-22-165-01) and [Johnson Controls](https://www.johnsoncontrols.com/cyber-solutions/security-advisories).