📦 Metasys Open Application Server

by Johnsoncontrols

🔍 What is Metasys Open Application Server?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2022-21938

HIGH CVSS 8.1 Jun 15, 2022

This cross-site scripting (XSS) vulnerability in Johnson Controls Metasys building automation systems allows attackers to inject malicious scripts into the MUI Graphics web interface. When exploited, ...

CVE-2022-21935

HIGH CVSS 7.5 Jun 15, 2022

This vulnerability in Johnson Controls Metasys building automation systems allows attackers to change passwords without verification. It affects Metasys ADS/ADX/OAS servers running vulnerable versions...

CVE-2022-21934

HIGH CVSS 8.0 May 6, 2022

This vulnerability in Metasys building automation servers allows authenticated users to lock out other users or take over their accounts. It affects Metasys ADS/ADX/OAS servers version 10 before 10.1....

CVE-2021-36207

HIGH CVSS 8.8 Apr 29, 2022

CVE-2021-36207 is a privilege escalation vulnerability in Johnson Controls Metasys ADS/ADX/OAS servers that allows authenticated users to elevate their privileges to administrator level. This affects ...

CVE-2021-36205

HIGH CVSS 8.1 Apr 15, 2022

CVE-2021-36205 is an authentication bypass vulnerability in Johnson Controls Metasys products where session tokens are not properly cleared on logout. This allows attackers to reuse valid session toke...