« Volver al listado

Johnsoncontrols

Johnsoncontrols Metasys System Configuration Tool: vulnerabilidades y CVE

Johnsoncontrols Metasys System Configuration Tool tiene 4 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE4
Últimos 12 meses0
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2022-21940Media (6.1)0.37%—9 feb 2023
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.
CVE-2022-21939Media (6.1)0.55%—9 feb 2023
Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.
CVE-2021-36203Crítica (9.1)0.87%—22 abr 2022
The affected product may allow an attacker to identify and forge requests to internal systems by way of a specially crafted request.
CVE-2020-9044Crítica (9.1)1.3%—10 mar 2020
XXE vulnerability exists in the Metasys family of product Web Services which has the potential to facilitate DoS attacks or harvesting of ASCII server files. This affects Johnson Controls' Metasys Application and Data…

Otros productos de Johnsoncontrols