QID 590919

Date Published: 2022-07-18

QID 590919: Johnson Controls Facility Explorer Multiple Vulnerabilities (JCI-PSA-2019-10 v1)

AFFECTED PRODUCTS
Affected versions of Facility Explorer: FX14.7.2, FX14.4, FX6.5

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

The first relates to a vulnerability that could allow a less privileged process to gain read-access to privileged files. The second relates to a vulnerability in the QNX proc filesystem service that could allow a less privileged process to gain access to a chosen process address space.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Medium - 4.6 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section JCI-PSA-2019-10 v1 for affected packages and patching details.

    CVEs related to QID 590919

    Software Advisories
    Advisory ID Software Component Link
    JCI-PSA-2019-10 v1 URL Logo www.johnsoncontrols.com/-/media/jci/cyber-solutions/product-security-advisories/2019/jci-psa-2019_10-v1-fx-supervisory-controller.pdf?la=en&hash=8A26E2FA4D1ACEB42E4FD59EE3419BE3A1B3E021