First published: Wed Jun 15 2022(Updated: )
Under certain circumstances, a vulnerability in Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 could allow a user to inject malicious code into the MUI Graphics web interface.
Credit: productsecurity@jci.com
Affected Software | Affected Version | How to fix |
---|---|---|
Johnson Controls, Inc. All Metasys ADS/ADX/OAS Versions 10 and 11 | ||
Johnson Controls Metasys | >=10.0<=10.1.5 | |
Johnson Controls Metasys | =11.0 | |
Johnson Controls Metasys | =11.0.1 | |
Johnsoncontrols Metasys Extended Application And Data Server | >=10.0<=10.1.5 | |
Johnsoncontrols Metasys Extended Application And Data Server | =11.0 | |
Johnsoncontrols Metasys Extended Application And Data Server | =11.0.1 | |
Johnson Controls Metasys | >=10.0<10.1.5 | |
Johnson Controls Metasys | =11.0 | |
Johnson Controls Metasys | =11.0.1 |
Update all Metasys ADS/ADX/OAS 10 versions with patch 10.1.5.
Update all Metasys ADS/ADX/OAS 11 versions with patch 11.0.2.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-21938.
CVE-2022-21938 has a severity of high (5.4).
Metasys ADS/ADX/OAS 10 versions prior to 10.1.5 and Metasys ADS/ADX/OAS 11 versions prior to 11.0.2 are affected by CVE-2022-21938.
Under certain circumstances, a user can inject malicious code into the MUI Graphics web interface of the affected software (Metasys ADS/ADX/OAS).
You can find more information about CVE-2022-21938 at the following references: [CISA Advisory](https://www.cisa.gov/uscert/ics/advisories/icsa-22-165-01) and [Johnson Controls Security Advisories](https://www.johnsoncontrols.com/cyber-solutions/security-advisories).