← Back to home
ICSA-19-227-01  ·  Published 2019-08-15  ·  View on CISA ICS-CERT ↗

Johnson Controls Metasys

CVSS 6.8 MEDIUM

Risk Summary

Successful exploitation of these vulnerabilities could be leveraged by an attacker to decrypt captured network traffic.

Remediations

  • Users should upgrade to Version 9.0 or later and configure sites with trusted certificates.
  • Further ICS security notices and product security guidance are located at the Johnson Controls product security website.
  • For questions concerning this product, contact Johnson Controls Global Product Security; email: [email protected].

Affected Vendors

Johnson Controls Inc

Affected Products (1)

Johnson Controls Inc · Metasys system < 9.0

Affected Sectors

Critical Manufacturing

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more