Johnson Controls Alert
2467Warning Date
Severity Level
Warning Number
Target Sector
24 April, 2022
● Medium
2022-4708
Manufacturing
Johnson Controls has released security updates to address a vulnerability in the following products:
- Metasys System Configuration Tool (SCT):
- All versions prior to 14.2.2
- Metasys System Configuration Tool Pro (SCT Pro):
- All versions prior to 14.2.2
An attacker could exploit this vulnerability by conducting a Server-side request forgery (SSRF).
The CERT team encourages users to review Johnson Controls security advisory and apply the necessary updates: