ICSA-23-012-06: Johnson controls metasys ads/adx/oas vulnerability
Affected Software
2 affected componentsFixes available
Johnson Controls Metasys ADS/ADX/OAS Version 10.X<10.1.6
10.1.6
Johnson Controls Metasys ADS/ADX/OAS Version 11.X<11.0.3
11.0.3
Event History
Feb 22, 2025
Advisory Published
11:35 PM
Frequently Asked Questions
1
What is the severity of ICSA-23-012-06?
The severity of ICSA-23-012-06 is rated as high due to the potential for unauthorized access and control of systems.
2
How do I fix ICSA-23-012-06?
To fix ICSA-23-012-06, apply the latest security updates provided by Johnson Controls for Metasys versions 10.X and 11.X.
3
What vulnerabilities are addressed in ICSA-23-012-06?
ICSA-23-012-06 addresses vulnerabilities that could allow an attacker to exploit improper authentication and access controls.
4
Which versions of Johnson Controls products are affected by ICSA-23-012-06?
Johnson Controls Metasys ADS/ADX/OAS versions 10.X and 11.X are affected by ICSA-23-012-06.
5
What should organizations using affected Johnson Controls products do regarding ICSA-23-012-06?
Organizations should review and assess their systems for exposure and prioritize applying the vendor's recommended security patches.