XXE vulnerability exists in the Metasys family of product Web Services which has the potential to facilitate DoS attacks or harvesting of ASCII server files. This affects Johnson Controls' Metasys Application and Data Server (ADS, ADS-Lite) versions 10.1 and prior; Metasys Extended Application and Data Server (ADX) versions 10.1 and prior; Metasys Open Data Server (ODS) versions 10.1 and prior; Metasys Open Application Server (OAS) version 10.1; Metasys Network Automation Engine (NAE55 only) versions 9.0.1, 9.0.2, 9.0.3, 9.0.5, 9.0.6; Metasys Network Integration Engine (NIE55/NIE59) versions 9.0.1, 9.0.2, 9.0.3, 9.0.5, 9.0.6; Metasys NAE85 and NIE85 versions 10.1 and prior; Metasys LonWorks Control Server (LCS) versions 10.1 and prior; Metasys System Configuration Tool (SCT) versions 13.2 and prior; Metasys Smoke Control Network Automation Engine (NAE55, UL 864 UUKL/ORD-C100-13 UUKLC 10th Edition Listed) version 8.1.
Project Subscriptions
| Vendors | Products |
|---|---|
|
Johnsoncontrols
Subscribe
|
Metasys Application And Data Server
Subscribe
Metasys Extended Application And Data Server
Subscribe
Metasys Lonworks Control Server
Subscribe
Metasys Open Application Server
Subscribe
Metasys Open Data Server
Subscribe
Metasys System Configuration Tool
Subscribe
Nae55
Subscribe
Nae55 Firmware
Subscribe
Nae85
Subscribe
Nae85 Firmware
Subscribe
Nie55
Subscribe
Nie55 Firmware
Subscribe
Nie59
Subscribe
Nie59 Firmware
Subscribe
Nie85
Subscribe
Nie85 Firmware
Subscribe
Ord-c100-13 Uuklc
Subscribe
Ord-c100-13 Uuklc Firmware
Subscribe
Ul 864 Uukl
Subscribe
Ul 864 Uukl Firmware
Subscribe
|
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2020-29873 | XXE vulnerability exists in the Metasys family of product Web Services which has the potential to facilitate DoS attacks or harvesting of ASCII server files. This affects Johnson Controls' Metasys Application and Data Server (ADS, ADS-Lite) versions 10.1 and prior; Metasys Extended Application and Data Server (ADX) versions 10.1 and prior; Metasys Open Data Server (ODS) versions 10.1 and prior; Metasys Open Application Server (OAS) version 10.1; Metasys Network Automation Engine (NAE55 only) versions 9.0.1, 9.0.2, 9.0.3, 9.0.5, 9.0.6; Metasys Network Integration Engine (NIE55/NIE59) versions 9.0.1, 9.0.2, 9.0.3, 9.0.5, 9.0.6; Metasys NAE85 and NIE85 versions 10.1 and prior; Metasys LonWorks Control Server (LCS) versions 10.1 and prior; Metasys System Configuration Tool (SCT) versions 13.2 and prior; Metasys Smoke Control Network Automation Engine (NAE55, UL 864 UUKL/ORD-C100-13 UUKLC 10th Edition Listed) version 8.1. |
Fixes
Solution
Johnson Controls has developed a patch to address this issue. Customers should contact their local branch office for remediation.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: jci
Published:
Updated: 2024-08-04T10:19:19.812Z
Reserved: 2020-02-18T00:00:00
Link: CVE-2020-9044
No data.
Status : Modified
Published: 2020-03-10T20:15:22.197
Modified: 2024-11-21T05:39:53.377
Link: CVE-2020-9044
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD