ICSA-22-298-05: Johnson controls cevas vulnerability
Affected Software
1 affected component
CKS, a subsidiary of Johnson Controls Inc. All CEVAS versions prior to 1.01.46
Event History
Feb 22, 2025
Advisory Published
11:35 PM
Frequently Asked Questions
1
What is the severity of ICSA-22-298-05?
The severity of ICSA-22-298-05 is rated as high due to potential exploitation that could lead to unauthorized access and control.
2
How do I fix ICSA-22-298-05?
To fix ICSA-22-298-05, update all vulnerable CEVAS versions to version 1.01.46 or later.
3
What systems are affected by ICSA-22-298-05?
ICSA-22-298-05 impacts all prior versions of CEVAS software produced by CKS, a subsidiary of Johnson Controls Inc.
4
What type of vulnerability is described in ICSA-22-298-05?
ICSA-22-298-05 describes a vulnerability that could allow an attacker to gain unauthorized access to sensitive components of the system.
5
Are there any mitigations for ICSA-22-298-05?
No specific mitigations are provided for ICSA-22-298-05; the only recommended action is to upgrade to the fixed version.