johnsoncontrols has 3 CVEs on record between 2018 and 2026. The median CVSS is 5.3 (medium), with 1 rated critical.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.3
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Products
- bcpro 1
- easyio_cpt_graphics 1
- frick_controls_quantum_hd_firmware 1
Worst active — by depth score
CVE-2026-21660Critical· 9.8A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, an…54CVE-2022-26643Medium· 5.3An issue in EasyIO CPT Graphics v0.8 allows attackers to discover valid users in the application.29CVE-2018-10624Medium· 4.3In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could allow an attacker to…24
johnsoncontrols vulnerabilities
CVEs affecting johnsoncontrols, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-21660Critical· 9.8A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, an…
A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, an…
CVE-2022-26643Medium· 5.3An issue in EasyIO CPT Graphics v0.8 allows attackers to discover valid users in the application.
An issue in EasyIO CPT Graphics v0.8 allows attackers to discover valid users in the application.
CVE-2018-10624Medium· 4.3In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could allow an attacker to…
In Johnson Controls Metasys System Versions 8.0 and prior and BCPro (BCM) all versions prior to 3.0.2, this vulnerability results from improper error handling in HTTP-based communications with the server, which could allow an attacker to…