Where
-Infinity
0

Vendor Risk Score

See how johnsoncontrols compares to other vendors in security performance

View Risk Score →

Software

johnsoncontrols frick controls quantum hd
6
johnsoncontrols frick controls quantum hd firmware
6
johnsoncontrols fms employee
3
johnsoncontrols metasys extended application and data server
3
johnsoncontrols c-cure 9000 firmware
2
johnsoncontrols exacqvision web service
2
johnsoncontrols metasys application and data server
2
johnsoncontrols metasys open application server
2
johnsoncontrols nae55 firmware
2
johnsoncontrols network automation engine 5510-2u
2
johnsoncontrols c-cure 9000
1
johnsoncontrols easyio cpt graphics
1
johnsoncontrols edge g2
1
johnsoncontrols edge g2 firmware
1
johnsoncontrols exacqvision enterprise manager
1
johnsoncontrols iosmart gen 1 firmware
1
johnsoncontrols istar ultra
1
johnsoncontrols istar ultra firmware
1
johnsoncontrols istar ultra g2
1
johnsoncontrols istar ultra g2 firmware
1
johnsoncontrols istar ultra lt
1
johnsoncontrols istar ultra lt firmware
1
johnsoncontrols kantech entrapass
1
johnsoncontrols metasys for validated environments
1
johnsoncontrols metasys lonworks control server
1
johnsoncontrols metasys open data server
1
johnsoncontrols metasys reporting engine
1
johnsoncontrols metasys system configuration tool
1
johnsoncontrols nae55
1
johnsoncontrols nae85
1
johnsoncontrols nae85 firmware
1
johnsoncontrols network controller
1
johnsoncontrols network controller firmware
1
johnsoncontrols nie55
1
johnsoncontrols nie55 firmware
1
johnsoncontrols nie59
1
johnsoncontrols nie59 firmware
1
johnsoncontrols nie85
1
johnsoncontrols nie85 firmware
1
johnsoncontrols ord-c100-13 uuklc
1
johnsoncontrols ord-c100-13 uuklc firmware
1
johnsoncontrols qolsys iq4 hub firmware
1
johnsoncontrols quantum hd unity acuair
1
johnsoncontrols quantum hd unity acuair firmware
1
johnsoncontrols quantum hd unity compressor
1
johnsoncontrols quantum hd unity compressor firmware
1
johnsoncontrols quantum hd unity condenser\/vessel
1
johnsoncontrols quantum hd unity condenser\/vessel firmware
1
johnsoncontrols quantum hd unity engine room
1
johnsoncontrols quantum hd unity engine room firmware
1
Severity
10
AV:N/AC:L/Au:N/C:C/I:C/A:C

Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote attackers to execute arbitrary code by uploading a shell script.

First published (updated )
Severity
10
Input Validation
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

A vulnerability with the SmartService API Service option exists whereby an unauthorized user could potentially exploit this to upload malicious code to the server that could be executed at system level privileges. This affects Johnson Controls' Kantech EntraPass Corporate Edition versions 8.0 and prior; Kantech EntraPass Global Edition versions 8.0 and prior.

Remedy

Upgrade impacted Kantech EntraPass Global and Corporate edition software to version 8.10.
First published (updated )
Severity
10
Command Injection
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauthenticated user root access to the system.

Remedy

Upgrade iSTAR Ultra firmware to version 6.8.9.CU01. The firmware can be downloaded here: https://www.swhouse.com/Support/SoftwareDownloads.aspx
First published (updated )
Severity
10
XSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

All versions of CEVAS prior to 1.01.46 do not sufficiently validate user-controllable input and could allow a user to bypass authentication and retrieve data with specially crafted SQL queries.

Remedy

Upgrade CEVAS to version 1.01.46. Contact CKS for the upgrade.
First published (updated )
Severity
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unauthorized user under certain circumstances.

Remedy

Update all OpenBlue Enterprise Manager Data Collector firmware to version 3.2.5.75.

Remedy

Contact your Customer Success Manager to obtain the update.
First published (updated )
Severity
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.

Remedy

Update all Quantum HD Unity Compressor control panels to firmware version 11.22 (Q5) or 12.22 (Q6).

Remedy

Update all Quantum HD Unity AcuAir control panels to firmware version 11.12 (Q5) or 12.12 (Q6).

Remedy

Update all Quantum HD Unity Condenser/Vessel control panels to firmware version 11.11 (Q5) or 12.11 (Q6).

Remedy

Update all Quantum HD Unity Evaporator control panels to firmware version 11.11 (Q5) or 12.11 (Q6).

Remedy

Update all Quantum HD Unity Engine Room control panels to firmware version 11.11 (Q5) or 12.11 (Q6).

Remedy

Update all Quantum HD Unity Interface control panels to firmware version 11.11 (Q5) or 12.11 (Q6).
First published (updated )
Severity
9.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

During installation or upgrade to Software House C•CURE 9000 v2.70 and American Dynamics victor Video Management System v5.2, the credentials of the user used to perform the installation or upgrade are logged in a file. The install log file persists after the installation.

Remedy

All users should upgrade to the latest version. Please note that while the upgrade will automatically remove the log file, we recommend existing deployments to securely delete the log file from the following path c:\ProgramData\Tyco\InstallerTemp and then change the password for the affected user account.
First published (updated )
Severity
9.8
Infoleak
AV:P/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:H

Under certain circumstances IQ Panel4 and IQ4 Hub panel software prior to version 4.4.2 could allow unauthorized access to settings.

Remedy

Upgrade IQ Panel 4 to version 4.4.2.

Remedy

Upgrade IQ4 Hub to version 4.4.2.

Remedy

The firmware can be updated remotely to all available devices in the field.

Remedy

The firmware update can also be manually loaded by applying the patch tag “iqpanel4.4.2” on the device after navigating to its firmware update page.
First published (updated )
Severity
9.8
OS Command Injection, Command Injection
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows OS Command Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device before authentication occurs.This issue affects Frick Controls Quantum HD version 10.22 and prior.

Remedy

a. Quantum HD version 10.22 through Version 11 is a previous product platform and is End Of support platform and should be upgraded to new platform with Quantum HD Unity version 12 and above. The update procedure can be found here:  https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories
First published (updated )
Severity
9.8
Code Injection
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device before authentication occurs.This issue affects Frick Controls Quantum HD version 10.22 and prior.

Remedy

a. Quantum HD version 10.22 through Version 11 is a previous product platform and is End Of support platform and should be upgraded to new platform with Quantum HD Unity version 12 and above. The update procedure can be found here:  https://frickcontrolsblob.file.core.windows.net/frickweb1/Quantum-HD-Unity/Quantum_HD_Unity_Software... https://frickcontrolsblob.file.core.windows.net/frickweb1/Quantum-HD-Unity/Quantum_HD_Unity_Software_Update_Procedure.pdf b. After the upgrade to version 12 is completed, ensure full alignment with hardening guide and apply all relevant security configurations. d. For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2026-05 at the following location
First published (updated )
Severity
9.8
Code Injection
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device before authentication occurs.This issue affects Frick Controls Quantum HD version 10.22 and prior.

Remedy

a. Quantum HD version 10.22 through Version 11 is a previous product platform and is End Of support platform and should be upgraded to new platform with Quantum HD Unity version 12 and above.  The update procedure can be found here:  https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories
First published (updated )
Severity
9.8
Code Injection
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device before authentication occurs.This issue affects Frick Controls Quantum HD version 10.22 and prior.

Remedy

a. Quantum HD version 10.22 through Version 11 is a previous product platform and is End Of support platform and should be upgraded to new platform with Quantum HD Unity version 12 and above. The update procedure can be found here: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories
First published (updated )
Severity
9.8
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion (LFI) vulnerability in Johnson Controls Frick Controls Quantum HD allow an unauthenticated attacker to execute arbitrary code on the affected device, leading to full system compromise. This issue affects Frick Controls Quantum HD: Frick Controls Quantum HD version 10.22 and prior.

Remedy

a. Quantum HD version 10.22 through Version 11 is a previous product platform and is End Of support platform and should be upgraded to new platform with Quantum HD Unity version 12 and above. The update procedure can be found here: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories
First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Under certain configurations an unauthenticated remote user could be given access to credentials stored in the exacqVision Server.

Remedy

Upgrade exacqVision Web Service to version 21.09. Current users can obtain the critical software update from the Software Download location at: https://www.exacq.com/support/downloads.php
First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

A vulnerability in versions 10.1 through 10.5 of Johnson Controls CEM Systems AC2000 allows a remote attacker to access to the system without adequate authorization. This issue affects: Johnson Controls CEM Systems AC2000 10.1; 10.2; 10.3; 10.4; 10.5.

Remedy

Apply a patch to all affected versions and implementations. The fix will also be included in 10.5 Server Feature Pack 2, version 10.6 and all future releases. To access the patch, affected users should contact their CEM support team: https://www.cemsys.com/support/technical-helpdesk/
First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.

First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

An unauthorized user could gain account access to IQ Wifi 6 versions prior to 2.0.2 by conducting a brute force authentication attack.

Remedy

Upgrade IQ Wifi 6 firmware to version 2.0.2. The firmware update will be pushed to all available devices in the field. The firmware update can also be manually loaded by applying the patch tag “iqwifi2.0.2” on the device after navigating to its firmware update page.
First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Under certain circumstances the session token is not cleared on logout.

Remedy

Update all Metasys ADS/ADX/OAS 10 versions with patch 10.1.5

Remedy

Update all Metasys ADS/ADX/OAS 11 versions with patch 11.0.2
First published (updated )
Severity
9.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

A debug feature in Sensormatic Electronics Illustra Pro Gen 4 Dome and PTZ cameras allows a user to compromise credentials after a long period of sustained attack.

Remedy

Update Illustra Pro Gen 4 Dome to version 6.00.00

Remedy

Update Illustra Pro Gen 4 PTZ to version 6.00.00

Remedy

The camera can be upgraded via the web GUI using firmware provided by Illustra which can be found on www.illustracameras.com http://www.illustracameras.com . The firmware can also be upgraded using the Illustra Connect tool (Windows based) or Illustra Tools (mobile app) or victor/VideoEdge, which also provides bulk firmware upgrade capability. Please refer to the respective application documents for further information.
First published (updated )
Severity
9.1
XEE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

XXE vulnerability exists in the Metasys family of product Web Services which has the potential to facilitate DoS attacks or harvesting of ASCII server files. This affects Johnson Controls' Metasys Application and Data Server (ADS, ADS-Lite) versions 10.1 and prior; Metasys Extended Application and Data Server (ADX) versions 10.1 and prior; Metasys Open Data Server (ODS) versions 10.1 and prior; Metasys Open Application Server (OAS) version 10.1; Metasys Network Automation Engine (NAE55 only) versions 9.0.1, 9.0.2, 9.0.3, 9.0.5, 9.0.6; Metasys Network Integration Engine (NIE55/NIE59) versions 9.0.1, 9.0.2, 9.0.3, 9.0.5, 9.0.6; Metasys NAE85 and NIE85 versions 10.1 and prior; Metasys LonWorks Control Server (LCS) versions 10.1 and prior; Metasys System Configuration Tool (SCT) versions 13.2 and prior; Metasys Smoke Control Network Automation Engine (NAE55, UL 864 UUKL/ORD-C100-13 UUKLC 10th Edition Listed) version 8.1.

First published (updated )
Severity
9.1
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a hardcoded RC2 key for certain encryption operations involving the Site Management Portal (SMP).

Remedy

Upgrade Metasys® devices to Release 9.0 or later and configure sites with trusted certificates.
First published (updated )
Severity
9.1
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a shared RSA key pair for certain encryption operations involving the Site Management Portal (SMP).

Remedy

Upgrade Metasys® devices to Release 9.0 or later and configure sites with trusted certificates.
First published (updated )
Severity
9.1
SSRF
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

The affected product may allow an attacker to identify and forge requests to internal systems by way of a specially crafted request.

Remedy

Johnson Controls recommends users take the following steps to mitigate this vulnerability: Update SCT/SCT Pro with Patch 14.2.2 Take proper steps to minimize risks to all building automation systems. For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2022-03 v1
First published (updated )
Severity
9
Weak Encryption
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

Under certain circumstances the communication between exacqVision Client and exacqVision Server will use insufficient key length and exchange

First published (updated )
Severity
9
Command Injection, OS Command Injection
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

A vulnerability exists that could allow the execution of unauthorized code or operating system commands on systems running exacqVision Web Service versions 20.06.3.0 and prior and exacqVision Enterprise Manager versions 20.06.4.0 and prior. An attacker with administrative privileges could potentially download and run a malicious executable that could allow OS command injection on the system.

Remedy

Upgrade all versions of exacqVision Web Service to version 20.06.2.0 or higher Upgrade all versions of exacqVision Enterprise Manager to version 20.06.3.0 or higher Current users can obtain the critical software update from the Software Downloads location at https://www.exacq.com/support/downloads.php
First published (updated )
Severity
8.8
CSRF
AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N

Under certain circumstances the exacqVision Web Services may be susceptible to Cross-Site Request Forgery (CSRF)

Remedy

Update exacqVision Web Service to version 24.06
First published (updated )
Severity
8.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

A vulnerability in all versions of Kantech EntraPass Editions could potentially allow an authorized low-privileged user to gain full system-level privileges by replacing critical files with specifically crafted files.

Remedy

Upgrade all Kantech EntraPass Editions to version 8.23. Registered users can obtain the critical software update by downloading the zip file from the Software Downloads location at https://kantech.com/Support/SoftwareDownloads.aspx.
First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Successful exploitation of this vulnerability could give an authenticated Facility Explorer SNC Series Supervisory Controller (F4-SNC) user an unintended level of access to the controller’s file system, allowing them to access or modify system files by sending specifically crafted web messages to the F4-SNC.

Remedy

Apply a patch to the Facility Explorer SNC Series Supervisory Controllers (F4-SNC).
First published (updated )
Severity
8.8
Input Validation
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

An insecure client auto update feature in C-CURE 9000 can allow remote execution of lower privileged Windows programs.

Remedy

Upgrade to C-CURE 9000 version 2.80 or above. If this is not possible then follow published instructions for disabling the auto update feature located here https://support.swhouse.com/ and search for the document SWH-TAB-nID-000006545.
First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Successful exploitation of this vulnerability could give an authenticated Metasys user an unintended level of access to the server file system, allowing them to access or modify system files by sending specifically crafted web messages to the Metasys system. This issue affects: Johnson Controls Metasys version 11.0 and prior versions.

Remedy

For Metasys versions previous to 9.0: Upgrade to a supported release. This is true for all the items except for Metasys Release 8.1 UL/cUL 864 UUKL 10th Edition Smoke Control.

Remedy

For Metasys versions 9.0 (engine only), 10.0, 10.1, 11.0: Install patch.
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203