You are here

Johnson Controls Metasys (ICSA-19-227-01)

Johnson Controls Metasys (ICSA-19-227-01)

Created: Friday, August 16, 2019 - 16:21
Categories:
Cybersecurity

The NCCIC has published an advisory on reusing a nonce, key pair in encryption and on the use of hard-coded cryptographic key vulnerabilities in Johnson Controls Metasys. Versions prior to 9.0 are affected. Successful exploitation of these vulnerabilities could be leveraged by an attacker to decrypt captured network traffic. Johnson Controls recommends users upgrade to version 9.0 or later and configure sites with trusted certificates. The NCCIC also recommends a series of measures to mitigate the vulnerabilities. Read the advisory at CISA.