ICSA-19-227-01
·
Published 2019-08-15
·
View on CISA ICS-CERT ↗
Johnson Controls Metasys
CVSS 6.8
MEDIUM
Risk Summary
Successful exploitation of these vulnerabilities could be leveraged by an attacker to decrypt captured network traffic.
CVEs (2)
Remediations
- Users should upgrade to Version 9.0 or later and configure sites with trusted certificates.
- Further ICS security notices and product security guidance are located at the Johnson Controls product security website.
- For questions concerning this product, contact Johnson Controls Global Product Security; email: [email protected].
Affected Vendors
Johnson Controls Inc
Affected Products (1)
Johnson Controls Inc
·
Metasys system
< 9.0
Affected Sectors
Critical Manufacturing
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more