Johnson Controls alert
2626Warning Date
Severity Level
Warning Number
Target Sector
5 October, 2022
● High
2022-5308
All
Johnson Controls has released a security update to address a vulnerability in the following product:
- Metasys ADX Server
- version 12.0 running MVE
Attacker could exploit this vulnerability by allowing an Active Directory user to execute validated actions without providing a valid password.
The CERT team encourages users to review Johnson Controls security advisory and apply the necessary updates: