Johnson Controls Vulnerabilities and Affected Products
Vulnerabilities associated with Metasys.
Products
Clear product- exacqVision6 vulnerabilities
- Frick Controls Quantum HD6 vulnerabilities
- Metasys ADS/ADX/OAS server6 vulnerabilities
- American Dynamics Illustra Essentials Gen 44 vulnerabilities
- iSTAR Configuration Utility (ICU)4 vulnerabilities
- Metasys4 vulnerabilities
- exacqVision Web Service3 vulnerabilities
- FM Systems Employee3 vulnerabilities
- IQ Panels2, 2+, IQHub, IQPanel 4, PowerG3 vulnerabilities
- iSTAR Ultra G2, iSTAR Ultra G2 SE, iSTAR Edge G22 vulnerabilities
- iSTAR Ultra, iSTAR Ultra SE2 vulnerabilities
- Metasys versions prior to 9.02 vulnerabilities
- OpenBlue Enterprise Manager Data Collector2 vulnerabilities
- Software House C•CURE 90002 vulnerabilities
- System Configuration Tool (SCT)2 vulnerabilities
- American Dynamics victor Video Management System v5.21 vulnerability
- BCPro (BCM)1 vulnerability
- C-CURE 90001 vulnerability
- CCure 90001 vulnerability
- CCure 9000 and victor application server1 vulnerability
- CEM Systems AC20001 vulnerability
- CEVAS1 vulnerability
- C•CURE 90001 vulnerability
- C•CURE Web Client version 2.90 and prior (Note - This does not affect the new web-based C•CURE 9000 client that was introduced in C•CURE 9000 v2.90)1 vulnerability
- Entrapass1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-26385CRITICAL | Metasys product command injection vulnerability could allow remote SQL executionJohnson Controls Metasys component listed below have Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability . Successful exploitation of this vulnerability could allow remote SQL execution This issue affects * Metasys: Application and Data Server (ADS) installed with SQL Express deployed as part of the Metasys 14.1 and prior installation, * Extended Application and Data Server (ADX) installed with SQL Express deployed as part of the Metasys 14… CWE-77Jan 30, 2026 | CVSS9.5v4.0 | EPSS1.44% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-36205HIGH | Metasys session tokenUnder certain circumstances the session token is not cleared on logout. CWE-459Apr 15, 2022 | CVSS8.1v3.1 | EPSS0.997% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-36202HIGH | Metasys UIServer-Side Request Forgery (SSRF) vulnerability in Johnson Controls Metasys could allow an authenticated attacker to inject malicious code into the MUI PDF export feature. This issue affects: Johnson Controls Metasys All 10 versions versions prior to 10.1.5; All 11 versions versions prior to 11.0.2. CWE-918Apr 7, 2022 | CVSS8.4v3.1 | EPSS0.799% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-27657HIGH | Metasys Improper Privilege ManagementSuccessful exploitation of this vulnerability could give an authenticated Metasys user an unintended level of access to the server file system, allowing them to access or modify system files by sending specifically crafted web messages to the Metasys system. This issue affects: Johnson Controls Metasys version 11.0 and prior versions. CWE-269Jun 4, 2021 | CVSS8.8v3.1 | EPSS1.24% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |