Johnsoncontrols
Johnsoncontrols Frick Controls Quantum HD Firmware: vulnerabilidades y CVE
Johnsoncontrols Frick Controls Quantum HD Firmware tiene 6 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses6
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-21660 | Media (6.9) | 0.23% | — | 27 feb 2026 | A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of… |
| CVE-2026-21659 | Alta (8.7) | 0.92% | — | 27 feb 2026 | Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion (LFI) vulnerability in Johnson Controls Frick Controls Quantum HD allow an unauthenticated attacker to execute arbitrary code… |
| CVE-2026-21658 | Alta (8.8) | 0.64% | — | 27 feb 2026 | Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in… |
| CVE-2026-21657 | Alta (8.8) | 0.40% | — | 27 feb 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters may permit unexpected… |
| CVE-2026-21656 | Alta (8.8) | 0.40% | — | 27 feb 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters may permit unexpected… |
| CVE-2026-21654 | Alta (8.8) | 1.5% | — | 27 feb 2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows OS Command Injection. Insufficient validation of input in… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Johnsoncontrols
Metasys Extended Application AND Data Server · 12Metasys Application AND Data Server · 11Metasys Open Application Server · 10Exacqvision WEB Service · 8Easyio Fs32 · 7Metasys System Configuration Tool · 4Exacqvision Server · 4Metasys System · 3FMS Employee · 3C-cure 9000 Firmware · 3Istar Ultra Firmware · 2Airwall · 2