Johnsoncontrols
Johnsoncontrols Webctrl: vulnerabilidades y CVE
Johnsoncontrols Webctrl tiene 2 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE2
Últimos 12 meses2
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-25086 | Alta (7.7) | 0.15% | — | 21 mar 2026 | Under certain conditions, an attacker could bind to the same port used by WebCTRL. This could allow the attacker to craft and send malicious packets and impersonate the WebCTRL service without requiring code injection… |
| CVE-2026-24060 | Crítica (9.1) | 0.20% | — | 21 mar 2026 | Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted, and modified by an attacker. Valuable information such as the File Start Position and File Data can… |
Otros productos de Johnsoncontrols
Metasys Extended Application AND Data Server · 12Metasys Application AND Data Server · 11Metasys Open Application Server · 10Exacqvision WEB Service · 8Frick Controls Quantum HD Firmware · 6Metasys System Configuration Tool · 4Exacqvision Server · 4Metasys System · 3C-cure 9000 Firmware · 3FMS Employee · 3Istar Ultra Firmware · 2Airwall · 2