ICSA-22-125-01: Metasys ads/adx/oas servers vulnerability
Affected Software
1 affected component
Johnson Controls, Inc. Metasys ADS/ADX/OAS Servers: Versions 10 and 11
Event History
Feb 22, 2025
Advisory Published
11:35 PM
Frequently Asked Questions
1
What is the severity of ICSA-22-125-01?
The severity of ICSA-22-125-01 is rated as critical due to the potential for remote code execution.
2
What vulnerabilities are addressed in ICSA-22-125-01?
ICSA-22-125-01 addresses multiple vulnerabilities in Johnson Controls, Inc. Metasys ADS/ADX/OAS Servers that could allow an attacker to execute arbitrary code.
3
How do I fix ICSA-22-125-01?
To fix ICSA-22-125-01, organizations should apply the latest security patches and updates provided by Johnson Controls for versions 10 and 11 of Metasys.
4
Which software versions are affected by ICSA-22-125-01?
ICSA-22-125-01 affects Johnson Controls, Inc. Metasys ADS/ADX/OAS Servers, specifically versions 10 and 11.
5
What should I do if I cannot immediately update my system for ICSA-22-125-01?
If you cannot immediately update your system for ICSA-22-125-01, consider implementing network segmentation and access control measures to mitigate exposure.