CVE-2020-9044
Summary
| CVE | CVE-2020-9044 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-03-10 20:15:00 UTC |
| Updated | 2020-03-11 21:28:00 UTC |
| Description | XXE vulnerability exists in the Metasys family of product Web Services which has the potential to facilitate DoS attacks or harvesting of ASCII server files. This affects Johnson Controls' Metasys Application and Data Server (ADS, ADS-Lite) versions 10.1 and prior; Metasys Extended Application and Data Server (ADX) versions 10.1 and prior; Metasys Open Data Server (ODS) versions 10.1 and prior; Metasys Open Application Server (OAS) version 10.1; Metasys Network Automation Engine (NAE55 only) versions 9.0.1, 9.0.2, 9.0.3, 9.0.5, 9.0.6; Metasys Network Integration Engine (NIE55/NIE59) versions 9.0.1, 9.0.2, 9.0.3, 9.0.5, 9.0.6; Metasys NAE85 and NIE85 versions 10.1 and prior; Metasys LonWorks Control Server (LCS) versions 10.1 and prior; Metasys System Configuration Tool (SCT) versions 13.2 and prior; Metasys Smoke Control Network Automation Engine (NAE55, UL 864 UUKL/ORD-C100-13 UUKLC 10th Edition Listed) version 8.1. |
Risk And Classification
Problem Types: CWE-611
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Johnsoncontrols | Metasys Application And Data Server | All | All | All | All |
| Application | Johnsoncontrols | Metasys Application And Data Server | All | All | All | All |
| Application | Johnsoncontrols | Metasys Extended Application And Data Server | All | All | All | All |
| Application | Johnsoncontrols | Metasys Lonworks Control Server | All | All | All | All |
| Application | Johnsoncontrols | Metasys Open Application Server | 10.1 | All | All | All |
| Application | Johnsoncontrols | Metasys Open Application Server | 10.1 | All | All | All |
| Application | Johnsoncontrols | Metasys Open Data Server | All | All | All | All |
| Application | Johnsoncontrols | Metasys System Configuration Tool | All | All | All | All |
| Hardware | Johnsoncontrols | Nae55 | - | All | All | All |
| Hardware | Johnsoncontrols | Nae55 | - | All | All | All |
| Operating System | Johnsoncontrols | Nae55 Firmware | 8.1 | All | All | All |
| Operating System | Johnsoncontrols | Nae55 Firmware | 9.0.1 | All | All | All |
| Operating System | Johnsoncontrols | Nae55 Firmware | 9.0.2 | All | All | All |
| Operating System | Johnsoncontrols | Nae55 Firmware | 9.0.3 | All | All | All |
| Operating System | Johnsoncontrols | Nae55 Firmware | 9.0.5 | All | All | All |
| Operating System | Johnsoncontrols | Nae55 Firmware | 9.0.6 | All | All | All |
| Operating System | Johnsoncontrols | Nae55 Firmware | 8.1 | All | All | All |
| Operating System | Johnsoncontrols | Nae55 Firmware | 9.0.1 | All | All | All |
| Operating System | Johnsoncontrols | Nae55 Firmware | 9.0.2 | All | All | All |
| Operating System | Johnsoncontrols | Nae55 Firmware | 9.0.3 | All | All | All |
| Operating System | Johnsoncontrols | Nae55 Firmware | 9.0.5 | All | All | All |
| Operating System | Johnsoncontrols | Nae55 Firmware | 9.0.6 | All | All | All |
| Hardware | Johnsoncontrols | Nae85 | - | All | All | All |
| Hardware | Johnsoncontrols | Nae85 | - | All | All | All |
| Operating System | Johnsoncontrols | Nae85 Firmware | All | All | All | All |
| Hardware | Johnsoncontrols | Nie55 | - | All | All | All |
| Hardware | Johnsoncontrols | Nie55 | - | All | All | All |
| Operating System | Johnsoncontrols | Nie55 Firmware | 9.0.1 | All | All | All |
| Operating System | Johnsoncontrols | Nie55 Firmware | 9.0.2 | All | All | All |
| Operating System | Johnsoncontrols | Nie55 Firmware | 9.0.3 | All | All | All |
| Operating System | Johnsoncontrols | Nie55 Firmware | 9.0.5 | All | All | All |
| Operating System | Johnsoncontrols | Nie55 Firmware | 9.0.6 | All | All | All |
| Operating System | Johnsoncontrols | Nie55 Firmware | 9.0.1 | All | All | All |
| Operating System | Johnsoncontrols | Nie55 Firmware | 9.0.2 | All | All | All |
| Operating System | Johnsoncontrols | Nie55 Firmware | 9.0.3 | All | All | All |
| Operating System | Johnsoncontrols | Nie55 Firmware | 9.0.5 | All | All | All |
| Operating System | Johnsoncontrols | Nie55 Firmware | 9.0.6 | All | All | All |
| Hardware | Johnsoncontrols | Nie59 | - | All | All | All |
| Hardware | Johnsoncontrols | Nie59 | - | All | All | All |
| Operating System | Johnsoncontrols | Nie59 Firmware | 9.0.1 | All | All | All |
| Operating System | Johnsoncontrols | Nie59 Firmware | 9.0.2 | All | All | All |
| Operating System | Johnsoncontrols | Nie59 Firmware | 9.0.3 | All | All | All |
| Operating System | Johnsoncontrols | Nie59 Firmware | 9.0.5 | All | All | All |
| Operating System | Johnsoncontrols | Nie59 Firmware | 9.0.6 | All | All | All |
| Operating System | Johnsoncontrols | Nie59 Firmware | 9.0.1 | All | All | All |
| Operating System | Johnsoncontrols | Nie59 Firmware | 9.0.2 | All | All | All |
| Operating System | Johnsoncontrols | Nie59 Firmware | 9.0.3 | All | All | All |
| Operating System | Johnsoncontrols | Nie59 Firmware | 9.0.5 | All | All | All |
| Operating System | Johnsoncontrols | Nie59 Firmware | 9.0.6 | All | All | All |
| Hardware | Johnsoncontrols | Nie85 | - | All | All | All |
| Hardware | Johnsoncontrols | Nie85 | - | All | All | All |
| Operating System | Johnsoncontrols | Nie85 Firmware | All | All | All | All |
| Hardware | Johnsoncontrols | Ord-c100-13 Uuklc | - | All | All | All |
| Hardware | Johnsoncontrols | Ord-c100-13 Uuklc | - | All | All | All |
| Operating System | Johnsoncontrols | Ord-c100-13 Uuklc Firmware | 8.1 | All | All | All |
| Operating System | Johnsoncontrols | Ord-c100-13 Uuklc Firmware | 8.1 | All | All | All |
| Hardware | Johnsoncontrols | Ul 864 Uukl | - | All | All | All |
| Hardware | Johnsoncontrols | Ul 864 Uukl | - | All | All | All |
| Operating System | Johnsoncontrols | Ul 864 Uukl Firmware | 8.1 | All | All | All |
| Operating System | Johnsoncontrols | Ul 864 Uukl Firmware | 8.1 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Product Security Advisories | CONFIRM | www.johnsoncontrols.com | Vendor Advisory |
| Johnson Controls Metasys | CISA | CERT | www.us-cert.gov | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
LEGACY: Lukasz Rupala
There are currently no legacy QID mappings associated with this CVE.