Lucene search

K

Johnsoncontrols Security Vulnerabilities

cve
cve

CVE-2023-3548

An unauthorized user could gain account access to IQ Wifi 6 versions prior to 2.0.2 by conducting a brute force authentication attack.

9.8CVSS

9.4AI Score

0.002EPSS

2023-07-25 02:15 PM
17
cve
cve

CVE-2023-3749

A local user could edit the VideoEdge configuration file and interfere with VideoEdge operation.

7.1CVSS

5.4AI Score

0.0004EPSS

2023-08-03 08:15 PM
27
cve
cve

CVE-2023-4486

Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC engines prior to versions 11.0.6 and 12.0.4 and Facility Explorer F4-SNC engines prior to versions 11.0.6 and 12.0.4 to cause denial-of-service.

7.5CVSS

7.6AI Score

0.0005EPSS

2023-12-07 08:15 PM
20
cve
cve

CVE-2023-4804

An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.

10CVSS

9.3AI Score

0.001EPSS

2023-11-10 11:15 PM
54
cve
cve

CVE-2024-0242

Under certain circumstances IQ Panel4 and IQ4 Hub panel software prior to version 4.4.2 could allow unauthorized access to settings.

9.8CVSS

9.2AI Score

0.001EPSS

2024-02-08 08:15 PM
18
cve
cve

CVE-2024-0912

Under certain circumstances the Microsoft® Internet Information Server (IIS) used to host the C•CURE 9000 Web Server will log Microsoft Windows credential details within logs. There is no impact to non-web service interfaces C•CURE 9000 or prior versions

4.2CVSS

7AI Score

0.0004EPSS

2024-06-06 12:15 AM
39
cve
cve

CVE-2024-32758

Under certain circumstances the communication between exacqVision Client and exacqVision Server will use insufficient key length and exchange

7.5CVSS

6.6AI Score

0.001EPSS

2024-08-01 10:15 PM
24
cve
cve

CVE-2024-32862

Under certain circumstances the ExacqVision Web Services does not provide sufficient protection from untrusted domains.

8.1CVSS

6.6AI Score

0.001EPSS

2024-08-01 10:15 PM
36
cve
cve

CVE-2024-32863

Under certain circumstances the exacqVision Web Services may be susceptible to Cross-Site Request Forgery (CSRF)

8.8CVSS

6.7AI Score

0.001EPSS

2024-08-01 09:15 PM
24
cve
cve

CVE-2024-32864

Under certain circumstances exacqVision Web Services will not enforce secure web communications (HTTPS)

8.1CVSS

6.5AI Score

0.001EPSS

2024-08-01 09:15 PM
26
cve
cve

CVE-2024-32865

Under certain circumstances the exacqVision Server will not properly validate TLS certificates provided by connected devices.

7.3CVSS

6.5AI Score

0.001EPSS

2024-08-01 10:15 PM
23
cve
cve

CVE-2024-32931

Under certain circumstances the exacqVision Web Service can expose authentication token details within communications.

5.7CVSS

5.8AI Score

0.0005EPSS

2024-08-01 10:15 PM
24
Total number of security vulnerabilities62