Browse all 101 CVE security advisories affecting Johnson Controls. AI-powered Chinese analysis, POCs, and references for each vulnerability.
Johnson Controls operates as a global leader in building technologies, providing integrated solutions for heating, ventilation, air conditioning, and security systems. With 76 recorded Common Vulnerabilities and Exposures (CVEs), the company’s software ecosystem has historically been susceptible to remote code execution, cross-site scripting, and privilege escalation flaws. These vulnerabilities often stem from legacy components within its building management platforms, exposing critical infrastructure to potential unauthorized access or data exfiltration. While no single catastrophic public breach has defined its recent history, the sheer volume of disclosed CVEs highlights systemic challenges in securing interconnected industrial control systems. Security researchers frequently identify these weaknesses as entry points for lateral movement within enterprise networks. Consequently, maintaining rigorous patch management and network segmentation remains essential for mitigating risks associated with Johnson Controls’ extensive hardware and software footprint in commercial and industrial environments.
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2023-4804 | Quantum HD Unity — Quantum HD Unity Compressor CWE-489 | 10.0 | Critical | 2023-11-10 |
| CVE-2023-3548 | IQ Wifi 6 — IQ Wifi 6 CWE-307 | 8.3 | High | 2023-07-25 |
| CVE-2023-2025 | Exposure of Sensitive Information in OpenBlue Enterprise Manager Data Collector — OpenBlue Enterprise Manager Data Collector CWE-200 | 5.0 | Medium | 2023-05-18 |
| CVE-2023-2024 | Improper Authentication for OpenBlue Enterprise Manager Data Collector — OpenBlue Enterprise Manager Data Collector CWE-287 | 10.0 | Critical | 2023-05-18 |
| CVE-2022-21940 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in System Configuration Tool (SCT) — System Configuration Tool (SCT) CWE-614 | 7.5 | High | 2023-02-09 |
| CVE-2022-21939 | Sensitive cookie without 'HttpOnly' flag in System Configuration Tool (SCT) — System Configuration Tool (SCT) CWE-1004 | 7.5 | High | 2023-02-09 |
| CVE-2021-36204 | Insufficiently Protected Credentials in Metasys — Metasys ADS/ADX/OAS CWE-522 | 7.8 | High | 2023-01-13 |
| CVE-2021-36206 | CEVAS — CEVAS CWE-79 | 10.0 | Critical | 2022-10-28 |
| CVE-2021-36201 | CCURE Observable Response Discrepancy — C•CURE 9000 CWE-204 | 4.3 | Medium | 2022-10-11 |
| CVE-2022-21941 | iSTAR Ultra — iSTAR Ultra CWE-77 | 10.0 | Critical | 2022-08-31 |
| CVE-2021-36200 | Metasys ADS/ADX/OAS with MUI — Metasys ADS/ADX/OAS server CWE-306 | 5.3 | Medium | 2022-07-22 |
| CVE-2022-21938 | Metasys MUI Graphics XSS — Metasys ADS/ADX/OAS server CWE-79 | 8.1 | High | 2022-06-15 |
| CVE-2022-21935 | Metasys password guessing — Metasys ADS/ADX/OAS server CWE-620 | 7.5 | High | 2022-06-15 |
| CVE-2022-21937 | Metasys CSS — Metasys ADS/ADX/OAS server CWE-79 | 8.7 | High | 2022-06-15 |
| CVE-2022-21934 | Metasys Unverified Password Change — Metasys ADS/ADX/OAS server CWE-620 | 8.0 | High | 2022-05-06 |
| CVE-2021-36207 | Metasys privilege management — Metasys ADS/ADX/OAS server CWE-269 | 8.8 | High | 2022-04-29 |
| CVE-2021-36205 | Metasys session token — Metasys CWE-459 | 8.1 | High | 2022-04-15 |
| CVE-2021-36202 | Metasys UI — Metasys CWE-918 | 8.4 | High | 2022-04-07 |
| CVE-2021-36199 | VideoEdge — VideoEdge CWE-228 | 5.3 | Medium | 2022-01-14 |
| CVE-2021-36198 | Entrapass — Entrapass CWE-200 | 8.3 | High | 2021-12-06 |
| CVE-2021-27665 | exacqVision Server 32-bit — exacqVision Web Service CWE-190 | 7.5 | High | 2021-10-11 |
| CVE-2021-27664 | exacqVision Web Service — exacqVision Web Service CWE-269 | 9.8 | Critical | 2021-10-11 |
| CVE-2021-27662 | KT-1 Capture-replay — KT-1 CWE-294 | 8.6 | High | 2021-09-15 |
| CVE-2021-27663 | CEM Systems AC2000 — CEM Systems AC2000 CWE-285 | 8.2 | High | 2021-08-30 |
| CVE-2021-27661 | Facility Explorer — Facility Explorer SNC Series Supervisory Controllers (F4-SNC) CWE-269 | 8.8 | High | 2021-07-01 |
| CVE-2021-27660 | C-CURE 9000 — C-CURE 9000 CWE-20 | 8.8 | High | 2021-07-01 |
| CVE-2021-27659 | exacqVision Web Service CSS — exacqVision Web Service CWE-79 | 5.3 | Medium | 2021-06-24 |
| CVE-2021-27658 | exacqVision Enterprise Manager CSS — exacqVision Enterprise Manager CWE-79 | 4.3 | Medium | 2021-06-24 |
| CVE-2021-27657 | Metasys Improper Privilege Management — Metasys CWE-269 | 8.8 | High | 2021-06-04 |
| CVE-2021-27656 | exacqVision Web Services - Information Exposure — exacqVision Web Service version 20.12.2.0 and prior | 5.3 | Medium | 2021-03-18 |
This page lists every published CVE security advisory associated with Johnson Controls. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.