ICSA-22-104-02: Metasys ads/adx/oas servers vulnerability
Affected Software
1 affected component
Johnson Controls Inc. All Metasys ADS/ADX/OAS Servers: Versions 10 and 11
Event History
Feb 22, 2025
Advisory Published
11:35 PM
Frequently Asked Questions
1
What is the severity of ICSA-22-104-02?
The severity of ICSA-22-104-02 is rated as high due to potential unauthorized access and control over vulnerable systems.
2
How do I fix ICSA-22-104-02?
To fix ICSA-22-104-02, apply the necessary patches provided by Johnson Controls Inc. for All Metasys ADS/ADX/OAS Servers versions 10 and 11.
3
What systems are affected by ICSA-22-104-02?
ICSA-22-104-02 affects All Metasys ADS/ADX/OAS Servers from Johnson Controls Inc., specifically versions 10 and 11.
4
What type of vulnerability is addressed in ICSA-22-104-02?
ICSA-22-104-02 addresses vulnerabilities related to unauthorized access and potential control of the supervisory control and data acquisition (SCADA) systems.
5
Is there a workaround for ICSA-22-104-02 before applying the fix?
Temporary workarounds may include restricting network access to affected servers and implementing strong authentication measures while awaiting the patch.