Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Johnson Controls — Vulnerabilities & Security Advisories 101

Browse all 101 CVE security advisories affecting Johnson Controls. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Johnson Controls operates as a global leader in building technologies, providing integrated solutions for heating, ventilation, air conditioning, and security systems. With 76 recorded Common Vulnerabilities and Exposures (CVEs), the company’s software ecosystem has historically been susceptible to remote code execution, cross-site scripting, and privilege escalation flaws. These vulnerabilities often stem from legacy components within its building management platforms, exposing critical infrastructure to potential unauthorized access or data exfiltration. While no single catastrophic public breach has defined its recent history, the sheer volume of disclosed CVEs highlights systemic challenges in securing interconnected industrial control systems. Security researchers frequently identify these weaknesses as entry points for lateral movement within enterprise networks. Consequently, maintaining rigorous patch management and network segmentation remains essential for mitigating risks associated with Johnson Controls’ extensive hardware and software footprint in commercial and industrial environments.

CVE ID Title CVSS Severity Published
CVE-2020-9050 Metasys Reporting Engine (MRE) Web Services - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') — Metasys Reporting Engine (MRE) Web Services versions 2.0 and 2.1 7.5 High 2021-02-19
CVE-2020-9049 victor Web Client and C•CURE Web Client JSON Web Token (JWT) Vulnerability — victor Web Client version 5.6 and prior CWE-285 7.1 High 2020-11-19
CVE-2020-9048 victor Web Client - Arbitrary File Deletion Vulnerability — victor Web Client version 5.4.1 and prior CWE-285 7.1 High 2020-10-08
CVE-2020-9047 exacqVision Software - Improper Verification of Cryptographic Signature — exacqVision Web Service versions 20.03.2.0 and prior CWE-347 6.8 Medium 2020-06-26
CVE-2020-9046 Kantech EntraPass Security Management Software - System Permissions Vulnerability — Kantech EntraPass Security Management Software Special Edition versions 8.22 and prior CWE-284 8.8 High 2020-05-26
CVE-2020-9045 C•CURE 9000 and victor Video Management System - Cleartext storage of user credentials upon installation or upgrade of software. — Software House C•CURE 9000 v2.70 CWE-312 9.9 Critical 2020-05-21
CVE-2019-7589 Kantech EntraPass Improper Input Validation — Kantech EntraPass Corporate Edition CWE-20 9.8 Critical 2020-03-10
CVE-2020-9044 Metasys Improper Restriction of XML External Entity Reference — Metasys Application and Data Server (ADS, ADS-Lite) CWE-611 7.5 High 2020-03-10
CVE-2019-7594 Metasys use of hardcoded RC2 key — Metasys versions prior to 9.0 CWE-321 9.1 - 2019-08-20
CVE-2019-7593 Metasys use of shared RSA key pairs — Metasys versions prior to 9.0 CWE-323 7.5 - 2019-08-20
CVE-2018-10624 Johnson Controls Metasys and BCPro Generation of Error Message Containing Sensitive Information — Metasys System CWE-209 4.3 Medium 2018-08-01

This page lists every published CVE security advisory associated with Johnson Controls. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.