Where
-Infinity
0

Vendor Risk Score

See how johnsoncontrols compares to other vendors in security performance

View Risk Score →

Software

johnsoncontrols frick controls quantum hd
6
johnsoncontrols frick controls quantum hd firmware
6
johnsoncontrols fms employee
3
johnsoncontrols metasys extended application and data server
3
johnsoncontrols c-cure 9000 firmware
2
johnsoncontrols exacqvision web service
2
johnsoncontrols metasys application and data server
2
johnsoncontrols metasys open application server
2
johnsoncontrols nae55 firmware
2
johnsoncontrols network automation engine 5510-2u
2
johnsoncontrols c-cure 9000
1
johnsoncontrols easyio cpt graphics
1
johnsoncontrols edge g2
1
johnsoncontrols edge g2 firmware
1
johnsoncontrols exacqvision enterprise manager
1
johnsoncontrols iosmart gen 1 firmware
1
johnsoncontrols istar ultra
1
johnsoncontrols istar ultra firmware
1
johnsoncontrols istar ultra g2
1
johnsoncontrols istar ultra g2 firmware
1
johnsoncontrols istar ultra lt
1
johnsoncontrols istar ultra lt firmware
1
johnsoncontrols kantech entrapass
1
johnsoncontrols metasys for validated environments
1
johnsoncontrols metasys lonworks control server
1
johnsoncontrols metasys open data server
1
johnsoncontrols metasys reporting engine
1
johnsoncontrols metasys system configuration tool
1
johnsoncontrols nae55
1
johnsoncontrols nae85
1
johnsoncontrols nae85 firmware
1
johnsoncontrols network controller
1
johnsoncontrols network controller firmware
1
johnsoncontrols nie55
1
johnsoncontrols nie55 firmware
1
johnsoncontrols nie59
1
johnsoncontrols nie59 firmware
1
johnsoncontrols nie85
1
johnsoncontrols nie85 firmware
1
johnsoncontrols ord-c100-13 uuklc
1
johnsoncontrols ord-c100-13 uuklc firmware
1
johnsoncontrols qolsys iq4 hub firmware
1
johnsoncontrols quantum hd unity acuair
1
johnsoncontrols quantum hd unity acuair firmware
1
johnsoncontrols quantum hd unity compressor
1
johnsoncontrols quantum hd unity compressor firmware
1
johnsoncontrols quantum hd unity condenser\/vessel
1
johnsoncontrols quantum hd unity condenser\/vessel firmware
1
johnsoncontrols quantum hd unity engine room
1
johnsoncontrols quantum hd unity engine room firmware
1
Severity
6.9
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, and potential misuse or system compromise

This issue affects Frick Controls Quantum HD version 10.22 and prior.

First published (updated )
Severity
4.8
Malicious File Upload
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files.

This issue affects FM Systems Employee: before 2025.3.1.

First published (updated )
Severity
4.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data.

This issue affects XAAP Application: before 1.53.

First published (updated )
Severity
4.8
XSS
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Systems Employee allows Stored XSS.

This issue affects FM Systems Employee: before 2025.3.1.

First published (updated )
Severity
4.8
XSS
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site Scripting (XSS).

This issue affects FM Systems Employee: before 2025.3.1.

First published (updated )
Severity
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

An issue in EasyIO CPT Graphics v0.8 allows attackers to discover valid users in the application.

First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.

First published (updated )
Severity
9.1
XEE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

XXE vulnerability exists in the Metasys family of product Web Services which has the potential to facilitate DoS attacks or harvesting of ASCII server files. This affects Johnson Controls' Metasys Application and Data Server (ADS, ADS-Lite) versions 10.1 and prior; Metasys Extended Application and Data Server (ADX) versions 10.1 and prior; Metasys Open Data Server (ODS) versions 10.1 and prior; Metasys Open Application Server (OAS) version 10.1; Metasys Network Automation Engine (NAE55 only) versions 9.0.1, 9.0.2, 9.0.3, 9.0.5, 9.0.6; Metasys Network Integration Engine (NIE55/NIE59) versions 9.0.1, 9.0.2, 9.0.3, 9.0.5, 9.0.6; Metasys NAE85 and NIE85 versions 10.1 and prior; Metasys LonWorks Control Server (LCS) versions 10.1 and prior; Metasys System Configuration Tool (SCT) versions 13.2 and prior; Metasys Smoke Control Network Automation Engine (NAE55, UL 864 UUKL/ORD-C100-13 UUKLC 10th Edition Listed) version 8.1.

First published (updated )
Severity
9.8
OS Command Injection, Command Injection
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows OS Command Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device before authentication occurs.This issue affects Frick Controls Quantum HD version 10.22 and prior.

Remedy

a. Quantum HD version 10.22 through Version 11 is a previous product platform and is End Of support platform and should be upgraded to new platform with Quantum HD Unity version 12 and above. The update procedure can be found here:  https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories
First published (updated )
Severity
9.8
Code Injection
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device before authentication occurs.This issue affects Frick Controls Quantum HD version 10.22 and prior.

Remedy

a. Quantum HD version 10.22 through Version 11 is a previous product platform and is End Of support platform and should be upgraded to new platform with Quantum HD Unity version 12 and above. The update procedure can be found here:  https://frickcontrolsblob.file.core.windows.net/frickweb1/Quantum-HD-Unity/Quantum_HD_Unity_Software... https://frickcontrolsblob.file.core.windows.net/frickweb1/Quantum-HD-Unity/Quantum_HD_Unity_Software_Update_Procedure.pdf b. After the upgrade to version 12 is completed, ensure full alignment with hardening guide and apply all relevant security configurations. d. For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-05 at the following location
First published (updated )
Severity
9.8
Code Injection
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device before authentication occurs.This issue affects Frick Controls Quantum HD version 10.22 and prior.

Remedy

a. Quantum HD version 10.22 through Version 11 is a previous product platform and is End Of support platform and should be upgraded to new platform with Quantum HD Unity version 12 and above.  The update procedure can be found here:  https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories
First published (updated )
Severity
9.8
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion (LFI) vulnerability in Johnson Controls Frick Controls Quantum HD allow an unauthenticated attacker to execute arbitrary code on the affected device, leading to full system compromise. This issue affects Frick Controls Quantum HD: Frick Controls Quantum HD version 10.22 and prior.

Remedy

a. Quantum HD version 10.22 through Version 11 is a previous product platform and is End Of support platform and should be upgraded to new platform with Quantum HD Unity version 12 and above. The update procedure can be found here: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories
First published (updated )
Severity
9.8
Code Injection
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device before authentication occurs.This issue affects Frick Controls Quantum HD version 10.22 and prior.

Remedy

a. Quantum HD version 10.22 through Version 11 is a previous product platform and is End Of support platform and should be upgraded to new platform with Quantum HD Unity version 12 and above. The update procedure can be found here: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories
First published (updated )
Severity
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.

Remedy

Update all Quantum HD Unity Compressor control panels to firmware version 11.22 (Q5) or 12.22 (Q6).

Remedy

Update all Quantum HD Unity AcuAir control panels to firmware version 11.12 (Q5) or 12.12 (Q6).

Remedy

Update all Quantum HD Unity Condenser/Vessel control panels to firmware version 11.11 (Q5) or 12.11 (Q6).

Remedy

Update all Quantum HD Unity Evaporator control panels to firmware version 11.11 (Q5) or 12.11 (Q6).

Remedy

Update all Quantum HD Unity Engine Room control panels to firmware version 11.11 (Q5) or 12.11 (Q6).

Remedy

Update all Quantum HD Unity Interface control panels to firmware version 11.11 (Q5) or 12.11 (Q6).
First published (updated )
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC engines prior to

versions 11.0.6 and 12.0.4

and Facility Explorer F4-SNC engines prior to versions 11.0.6 and 12.0.4 to cause denial-of-service.

Remedy

Update Metasys NAE55, SNE, and SNC engines to version 12.0.4.

Remedy

Update Metasys NAE55, SNE, and SNC engines to version 11.0.6.

Remedy

Update Facility Explorer F4-SNC engine to version 12.0.4.

Remedy

Update Facility Explorer F4-SNC engine to version 11.0.6.  

Remedy

For more information, contact your local Johnson Controls office or Authorized Building Control Specialists (ABCS).
First published (updated )
Severity
5.3
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Under certain circumstances a CCURE Portal user could enumerate user accounts in CCURE 9000 version 2.90 and prior versions.

Remedy

Update C•CURE 9000 2.90 with patch 2.90 SP5 or upgrade C•CURE 9000 to version 3.0. The software can be downloaded here: https://www.swhouse.com/Support/SoftwareDownloads.aspx
First published (updated )
Severity
10
XSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

All versions of CEVAS prior to 1.01.46 do not sufficiently validate user-controllable input and could allow a user to bypass authentication and retrieve data with specially crafted SQL queries.

Remedy

Upgrade CEVAS to version 1.01.46. Contact CKS for the upgrade.
First published (updated )
Severity
7.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Under some circumstances an Insufficiently Protected Credentials vulnerability in Johnson Controls Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.3 allows API calls to expose credentials in plain text.

Remedy

Update all Metasys ADS/ADX/OAS 10 versions with patch 10.1.6.

Remedy

Update all Metasys ADS/ADX/OAS 11 versions with patch 11.0.3.
First published (updated )
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.

Remedy

Update SCT version 14 with patch 14.2.3

Remedy

Update SCT version 15 with patch 15.0.3

Remedy

Contact your local Johnson Controls office or Authorized Building Control Specialists (ABCS).
First published (updated )
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.

Remedy

Update SCT version 14 with patch 14.2.3

Remedy

Update SCT version 15 with patch 15.0.3

Remedy

Contact your local Johnson Controls office or Authorized Building Control Specialists (ABCS).
First published (updated )
Severity
6.5
Infoleak
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 may expose sensitive information to an unauthorized user under certain circumstances.

Remedy

Update all OpenBlue Enterprise Manager Data Collector firmware to version 3.2.5.75.

Remedy

Contact your Customer Success Manager to obtain the update.
First published (updated )
Severity
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unauthorized user under certain circumstances.

Remedy

Update all OpenBlue Enterprise Manager Data Collector firmware to version 3.2.5.75.

Remedy

Contact your Customer Success Manager to obtain the update.
First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

A debug feature in Sensormatic Electronics Illustra Pro Gen 4 Dome and PTZ cameras allows a user to compromise credentials after a long period of sustained attack.

Remedy

Update Illustra Pro Gen 4 Dome to version 6.00.00

Remedy

Update Illustra Pro Gen 4 PTZ to version 6.00.00

Remedy

The camera can be upgraded via the web GUI using firmware provided by Illustra which can be found on www.illustracameras.com http://www.illustracameras.com . The firmware can also be upgraded using the Illustra Connect tool (Windows based) or Illustra Tools (mobile app) or victor/VideoEdge, which also provides bulk firmware upgrade capability. Please refer to the respective application documents for further information.
First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

An unauthorized user could gain account access to IQ Wifi 6 versions prior to 2.0.2 by conducting a brute force authentication attack.

Remedy

Upgrade IQ Wifi 6 firmware to version 2.0.2. The firmware update will be pushed to all available devices in the field. The firmware update can also be manually loaded by applying the patch tag “iqwifi2.0.2” on the device after navigating to its firmware update page.
First published (updated )
Severity
7.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N

A local user could edit the VideoEdge configuration file and interfere with VideoEdge operation.

Remedy

Update VideoEdge to version 6.1.1. The update can be downloaded from www.americandynamics.net http://www.americandynamics.net under Support/Software Downloads/Network Video Recorders.
First published (updated )
Severity
7.5
Infoleak
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

An attacker with physical access to the Kantech Gen1 ioSmart card reader with firmware version prior to 1.07.02 in certain circumstances can recover the reader's communication memory between the card and reader.

Remedy

Update ioSmart Gen1 card reader to firmware version 1.07.02 or higher. Download the update here:  https://www.kantech.com/Resources/GetDoc.aspx?p=1&id=58679 https://www.kantech.com/Resources/GetDoc.aspx Contact technical support for additional information. ioSmart Gen2 readers are not affected by this behavior. Contact your local sales representative for ordering information.
First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Under certain configurations an unauthenticated remote user could be given access to credentials stored in the exacqVision Server.

Remedy

Upgrade exacqVision Web Service to version 21.09. Current users can obtain the critical software update from the Software Download location at: https://www.exacq.com/support/downloads.php
First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems AC2000 allows a remote attacker to access to the system without adequate authorization. This issue affects: Johnson Controls CEM Systems AC2000 10.1; 10.2; 10.3; 10.4; 10.5.

Remedy

Apply a patch to all affected versions and implementations. The fix will also be included in 10.5 Server Feature Pack 2, version 10.6 and all future releases. To access the patch, affected users should contact their CEM support team: https://www.cemsys.com/support/technical-helpdesk/
First published (updated )
Severity
7.5
Infoleak
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

A vulnerability in exacqVision Web Service 20.12.2.0 and prior could allow an unauthenticated attacker to view system-level information about the exacqVision Web Service and the operating system.

Remedy

Upgrade all versions of exacqVision Web Service to v21.03.3 or later. Web Service 21.03.3 or later will only provide a full response to health.web info when authorized. Users can obtain the software update by downloading the update found here: https://exacq.com/support/downloads.php.
First published (updated )
Severity
7.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

A vulnerability in specified versions of American Dynamics victor Web Client and Software House C•CURE Web Client could allow an unauthenticated attacker on the network to create and sign their own JSON Web Token and use it to execute an HTTP API Method without the need for valid authentication/authorization. Under certain circumstances, this could be used by an attacker to impact system availability by conducting a Denial of Service attack.

Remedy

victor Web Client • victor Web Client v5.6 and earlier – upgrade to v5.6 SP1 (victor Unified Client v5.6 SP1) Registered users can obtain the software update by downloading the update found here: https://www.americandynamics.net/support/SoftwareDownloads.aspx. C•CURE Web Client C•CURE Web v2.60 and earlier - upgrade to a minimum of v2.70 and install the relevant update below. • C•CURE Web v2.70 - install the update WebClient_c2.70_5.2_Update02 • C•CURE Web v2.80 - install the update WebClient_c2.80_v5.4.1_Update04 • C•CURE Web v2.90 - install the update CCureWeb_2.90_Update01 Registered users can obtain the software update by downloading the update found here: https://swhouse.com/Support/SoftwareDownloads.aspx.
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203