PT-2020-20457 · Johnson Controls · Metasys Nae85+9
Lukasz Rupala
·
Published
2020-03-10
·
Updated
2020-03-11
·
CVE-2020-9044
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Metasys Application and Data Server (ADS, ADS-Lite) versions prior to 10.1
Metasys Extended Application and Data Server (ADX) versions prior to 10.1
Metasys Open Data Server (ODS) versions prior to 10.1
Metasys Open Application Server (OAS) version 10.1
Metasys Network Automation Engine (NAE55 only) versions 9.0.1, 9.0.2, 9.0.3, 9.0.5, 9.0.6
Metasys Network Integration Engine (NIE55/NIE59) versions 9.0.1, 9.0.2, 9.0.3, 9.0.5, 9.0.6
Metasys NAE85 and NIE85 versions prior to 10.1
Metasys LonWorks Control Server (LCS) versions prior to 10.1
Metasys System Configuration Tool (SCT) versions prior to 13.2
Metasys Smoke Control Network Automation Engine (NAE55, UL 864 UUKL/ORD-C100-13 UUKLC 10th Edition Listed) version 8.1
Description
An XXE vulnerability exists in the Metasys family of product Web Services, which has the potential to facilitate DoS attacks or harvesting of ASCII server files.
Recommendations
For Metasys Application and Data Server (ADS, ADS-Lite) versions prior to 10.1, update to a version later than 10.1.
For Metasys Extended Application and Data Server (ADX) versions prior to 10.1, update to a version later than 10.1.
For Metasys Open Data Server (ODS) versions prior to 10.1, update to a version later than 10.1.
For Metasys Open Application Server (OAS) version 10.1, update to a version later than 10.1.
For Metasys Network Automation Engine (NAE55 only) versions 9.0.1, 9.0.2, 9.0.3, 9.0.5, 9.0.6, update to a version later than 9.0.6.
For Metasys Network Integration Engine (NIE55/NIE59) versions 9.0.1, 9.0.2, 9.0.3, 9.0.5, 9.0.6, update to a version later than 9.0.6.
For Metasys NAE85 and NIE85 versions prior to 10.1, update to a version later than 10.1.
For Metasys LonWorks Control Server (LCS) versions prior to 10.1, update to a version later than 10.1.
For Metasys System Configuration Tool (SCT) versions prior to 13.2, update to a version later than 13.2.
For Metasys Smoke Control Network Automation Engine (NAE55, UL 864 UUKL/ORD-C100-13 UUKLC 10th Edition Listed) version 8.1, update to a version later than 8.1.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Metasys Application/Data Server
Metasys Extended Application/Data Server
Metasys Lonworks Control Server
Metasys Nae85
Metasys Network Automation Engine
Metasys Network Integration Engine
Metasys Open Application Server
Metasys Open Data Server
Metasys Smoke Control Network Automation Engine
Metasys System Configuration Tool