Johnson Controls

First CVE: Jun 18, 2019Active for: 7 years
89
CVEs Published
More CVEs Published than 69% of tracked CNAs
11.1
Avg CVEs / Year
More Avg CVEs / Year than 56% of tracked CNAs
7.7
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked CNAs
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published by Johnson Controls over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jun 18, 2019
7 years ago
Most Recent CVE
Jul 23, 2026
2 days ago

Top CVEs

All CVEs published by Johnson Controls as a CNA, regardless of affected vendor or product.

89 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A vulnerability exists that could allow the execution of unauthorized code or operating system commands on systems running exacqVision Web Service versions 20.06.3.0 and prior and
Jun 26, 20207.238NOYES
Deserialization of untrusted data vulnerability in Johnson Control victor on Windows allows capec-586. This issue affects victor: from 2.9 before 3.0.
Jul 23, 20268.736NONO
Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injectio
Feb 27, 20269.833NONO
Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233. This issue affects victor Web: before 7.1.
Jul 23, 20267.132NONO
Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery. This issue affects CCure 9000 and victor application ser
Jul 23, 20267.232NONO
Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to una
Feb 27, 20269.832NONO
Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion (LFI) vulnerability in Johnson Controls Frick Controls Quantum HD allow an unauthentica
Feb 27, 20269.832NONO
Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in cer
Feb 27, 20269.832NONO
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows OS Command Injection. 
Feb 27, 20269.832NONO
Johnson Controls Metasys component listed below have Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability . Successful exploitation of t
Jan 30, 20269.532NONO

CVE Severity & Scoring

Severity distribution of CVEs published by this CNA89 CVEs
Severity distribution among all CVEs352,427 CVEs
LowMediumHighCritical
Attack Vector
Local7 (7.9%)
Network71 (79.8%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network5 (5.6%)
Attack Complexity
Low82 (92.1%)
High7 (7.9%)
Unknown0 (0.0%)
User Interaction
None73 (82.0%)
Unknown0 (0.0%)
Required13 (14.6%)
Privileges Required
Low23 (25.8%)
High8 (9.0%)
None58 (65.2%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this cna scope (89 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
1.1% of CVEs· 81st percentile
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID published by Johnson Controls as a CNA.

Media Mentions

Media articles that mention a CVE ID published by Johnson Controls as a CNA — matched by CVE ID, not by organization name.

Top Affected Vendors

Top Affected Products

Top CWEs