Skip to main content

Vendor archive

johnsoncontrols CVEs

Beta · best-effort

72 CVEs tagged to vendor johnsoncontrols9 Critical, 37 High, 26 Medium, 0 Low, 0 Unrated.

CVE-2021-27659

Published Jun 24, 2021

exacqVision Web Service 21.03 does not sufficiently validate, filter, escape, and/or encode user-controllable input before it is placed in output that is used as a web page that i…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-27657

Published Jun 4, 2021

Successful exploitation of this vulnerability could give an authenticated Metasys user an unintended level of access to the server file system, allowing them to access or modify s…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-27656

Published Mar 18, 2021

A vulnerability in exacqVision Web Service 20.12.2.0 and prior could allow an unauthenticated attacker to view system-level information about the exacqVision Web Service and the o…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2020-9050

Published Feb 19, 2021

Path Traversal vulnerability exists in Metasys Reporting Engine (MRE) Web Services which could allow a remote unauthenticated attacker to access and download arbitrary files from…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2020-9046

Published May 26, 2020

A vulnerability in all versions of Kantech EntraPass Editions could potentially allow an authorized low-privileged user to gain full system-level privileges by replacing critical…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2019-7589

Published Mar 10, 2020

A vulnerability with the SmartService API Service option exists whereby an unauthorized user could potentially exploit this to upload malicious code to the server that could be ex…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2019-7594

Published Aug 20, 2019

Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a hardcoded RC2 key for certain encryption operations involving the Site Management Portal (SMP).

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-7593

Published Aug 20, 2019

Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a shared RSA key pair for certain encryption operations involving the Site Management Portal (SMP).

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2019-7590

Published Jul 19, 2019

ExacqVision Server’s services 'exacqVisionServer', 'dvrdhcpserver' and 'mdnsresponder' have an unquoted service path. If an authenticated user is able to insert code in their syst…

CVSS 6.7 · Medium
Vendor/product tagsBeta · best-effort
Showing 51-72 of 72 CVEsPage 3 of 3