Unknown
CVE-2020-9044
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below:
Add References:
CVE-2020-9044
MITRE ATT&CK
Collection
Command and Control
Credential Access
Defense Evasion
Discovery
Execution
Exfiltration
Impact
Initial Access
Lateral Movement
Persistence
Privilege Escalation
Topic Tags
Description
XXE vulnerability exists in the Metasys family of product Web Services which has the potential to facilitate DoS attacks or harvesting of ASCII server files. This affects Johnson Controls’ Metasys Application and Data Server (ADS, ADS-Lite) versions 10.1 and prior; Metasys Extended Application and Data Server (ADX) versions 10.1 and prior; Metasys Open Data Server (ODS) versions 10.1 and prior; Metasys Open Application Server (OAS) version 10.1; Metasys Network Automation Engine (NAE55 only) versions 9.0.1, 9.0.2, 9.0.3, 9.0.5, 9.0.6; Metasys Network Integration Engine (NIE55/NIE59) versions 9.0.1, 9.0.2, 9.0.3, 9.0.5, 9.0.6; Metasys NAE85 and NIE85 versions 10.1 and prior; Metasys LonWorks Control Server (LCS) versions 10.1 and prior; Metasys System Configuration Tool (SCT) versions 13.2 and prior; Metasys Smoke Control Network Automation Engine (NAE55, UL 864 UUKL/ORD-C100-13 UUKLC 10th Edition Listed) version 8.1.
Add Assessment
No one has assessed this topic. Be the first to add your voice to the community.
CVSS V3 Severity and Metrics
General Information
Vendors
Products
- metasys application and data server,
- metasys extended application and data server,
- metasys lonworks control server,
- metasys open application server 10.1,
- metasys open data server,
- metasys system configuration tool,
- nae55 firmware 8.1,
- nae55 firmware 9.0.1,
- nae55 firmware 9.0.2,
- nae55 firmware 9.0.3,
- nae55 firmware 9.0.5,
- nae55 firmware 9.0.6,
- nae85 firmware,
- nie55 firmware 9.0.1,
- nie55 firmware 9.0.2,
- nie55 firmware 9.0.3,
- nie55 firmware 9.0.5,
- nie55 firmware 9.0.6,
- nie59 firmware 9.0.1,
- nie59 firmware 9.0.2,
- nie59 firmware 9.0.3,
- nie59 firmware 9.0.5,
- nie59 firmware 9.0.6,
- nie85 firmware,
- ord-c100-13 uuklc firmware 8.1,
- ul 864 uukl firmware 8.1
Weaknesses
References
Additional Info
Technical Analysis
Report as Emergent Threat Response
Report as Zero-day Exploit
Report as Exploited in the Wild
CVE ID
AttackerKB requires a CVE ID in order to pull vulnerability data and references from the CVE list and the National Vulnerability Database. If available, please supply below: