CVEs we hold for Johnson
Records whose assigning authority named Johnson as the affected vendor. Newest identifiers first, capped at 200.
CVE-2026-27875Simplex Incident Manager Clear TestJohnson Controls Simplex Incident Manager / Autocall Fire…
CVE-2026-21660Johnson Controls-Frick Quantum HD-Hardcoded Email Credentials Saved as Plaintext in FirmwareJohnson Controls Frick Controls Quantum HD
CVE-2026-21659Johnson Controls -Frick Quantum HD-Unauthenticated Remote Code Execution and Information Disclosure due to Local File…Johnson Controls Frick Controls Quantum HD
CVE-2026-21658Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code ExecutionJohnson Controls Frick Controls Quantum HD
CVE-2026-21657Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code ExecutionJohnson Controls Frick Controls Quantum HD
CVE-2026-21656Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code ExecutionJohnson Controls Frick Controls Quantum HD
CVE-2026-21655C-CURE 9000 and Victor application server - Deserialization of Untrusted DataJohnson Controls Victor Application Server
CVE-2026-21654Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code ExecutionJohnson Controls Frick Controls Quantum HD
CVE-2026-21653CCure and Victor Application Server - Server Side Request ForgeryJohnson Controls CCure 9000 and victor application server
CVE-2025-61740Johnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG Origin Validation ErrorJohnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG
CVE-2025-61739Johnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG reusing a nonce, key pair in encryptionJohnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG
CVE-2025-61738Johnson Controls PowerG and IQPanel cleartext transmission of sensitive informationJohnson Controls IQPanel2, IQHub,IQPanel2+,IQPanel 4,PowerG
CVE-2025-61736iSTAR- Improper Validation of Certificate ExpirationJohnson Controls iSTAReX, iSTAR Edge, iSTAR Ultra LT, iSTAR…
CVE-2025-43876iSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, iSTAR Edge G2 - Authenticated web application command injection -…Johnson Controls iSTAR Ultra G2, iSTAR Ultra G2 SE, iSTAR…
CVE-2025-43875iSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, iSTAR Edge G2 - Authenticated web application command injection -…Johnson Controls iSTAR Ultra G2, iSTAR Ultra G2 SE, iSTAR…
CVE-2025-43873iSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, iSTAR Edge G2 - Authenticated web application command injection -…Johnson Control iSTAR Ultra, iSTAR Ultra SE, iSTAR Ultra…
CVE-2025-26386Stack-based Buffer Overflow in Johnson Controls iSTAR Configuration Utility (ICU) toolJohnson Controls iSTAR Configuration Utility (ICU)
CVE-2025-26385Metasys product command injection vulnerability could allow remote SQL executionJohnson Controls Metasys
CVE-2025-26382Johnson Controls Software House iSTAR Configuration Utility (ICU) ToolJohnson Controls iSTAR Configuration Utility (ICU)
CVE-2025-26381OpenBlue Mobile Web Application configuration issue for optional for OpenBlue Workplace (formerly FM Systems)Johnson Controls OpenBlue Workplace (formerly FM Systems)
CVE-2025-26379Johnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG use of Cryptographically Weak Pseudo-Random Number GeneratorJohnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG
CVE-2024-32932American Dynamics Illustra Essentials Gen 4 - Reversible User Credential - stored web interfaceJohnson Controls American Dynamics Illustra Essentials Gen 4
CVE-2024-32861Software House C•CURE - CouchDB executable protectionJohnson Controls Software House C•CURE 9000 Installer
CVE-2024-32759Johnson Controls Software House C●CURE 9000 installer password strengthJohnson Controls Software House C•CURE 9000
CVE-2024-32757American Dynamics Illustra Essentials Gen 4 - Linux Credential LeakJohnson Controls American Dynamics Illustra Essentials Gen 4
CVE-2024-32756American Dynamics Illustra Essentials Gen 4 - Reversible User Credential - LinuxJohnson Controls American Dynamics Illustra Essentials Gen 4
CVE-2024-32755American Dynamics Illustra Essentials Gen 4 - Log Filter Input ValidationJohnson Controls American Dynamics Illustra Essentials Gen 4
CVE-2024-32754Johnson Controls Kantech KT1, KT2, and KT400 Door Controllers - Exposure of Sensitive InformationJohnson Controls Kantech KT400 Door Controller, Rev01
CVE-2024-32753TYCO Illustra Pro Gen 4 - JQuery versionJohnson Controls TYCO Illustra Flex4 DualSensor Cameras
CVE-2024-32752Johnson Controls Software House iSTAR Configuration Utility (ICU) ToolJohnson Controls iSTAR Ultra and Ultra LT
CVE-2023-4486Uncontrolled Resource Consumption in Metasys and Facility ExplorerJohnson Controls Facility Explorer F4-SNC
CVE-2023-2025Exposure of Sensitive Information in OpenBlue Enterprise Manager Data CollectorJohnson Controls OpenBlue Enterprise Manager Data Collector
CVE-2023-2024Improper Authentication for OpenBlue Enterprise Manager Data CollectorJohnson Controls OpenBlue Enterprise Manager Data Collector
CVE-2022-21940Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in System Configuration Tool (SCT)Johnson Controls System Configuration Tool (SCT)
CVE-2022-21939Sensitive cookie without 'HttpOnly' flag in System Configuration Tool (SCT)Johnson Controls System Configuration Tool (SCT)
CVE-2021-27656exacqVision Web Services - Information ExposureJohnson Controls exacqVision Web Service version 20.12.2.0…
CVE-2020-9050Metasys Reporting Engine (MRE) Web Services - Improper Limitation of a Pathname to a Restricted Directory ('Path…Johnson Controls Metasys Reporting Engine (MRE) Web…
CVE-2020-9049victor Web Client and C•CURE Web Client JSON Web Token (JWT) VulnerabilityJohnson Controls C•CURE Web Client version 2.90 and prior…
CVE-2020-9048victor Web Client - Arbitrary File Deletion VulnerabilityJohnson Controls victor Web Client version 5.4.1 and prior
CVE-2020-9047exacqVision Software - Improper Verification of Cryptographic SignatureJohnson Controls exacqVision Enterprise Manager versions…
CVE-2020-9046Kantech EntraPass Security Management Software - System Permissions VulnerabilityJohnson Controls Kantech EntraPass Security Management…
CVE-2020-9045C•CURE 9000 and victor Video Management System - Cleartext storage of user credentials upon installation or upgrade of…Johnson Controls American Dynamics victor Video Management…
CVE-2020-9044Metasys Improper Restriction of XML External Entity ReferenceJohnson Controls Metasys Smoke Control Network Automation…
CVE-2019-7589Kantech EntraPass Improper Input ValidationJohnson Controls Kantech EntraPass Global Edition
CVE-2018-10624Johnson Controls Metasys and BCPro Generation of Error Message Containing Sensitive InformationJohnson Controls BCPro (BCM)
95 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.
Everything on this page is free. Public data. Withholding it protects nothing.