The NCCIC has published an advisory on reusing a nonce, key pair in encryption and on the use of hard-coded cryptographic key vulnerabilities in Johnson Controls Metasys. Versions prior to 9.0 are affected. Successful exploitation of these vulnerabilities could be leveraged by an attacker to decrypt captured network traffic. Johnson Controls recommends users upgrade to version 9.0 or later and configure sites with trusted certificates. The NCCIC also recommends a series of measures to mitigate the vulnerabilities. Read the advisory at CISA.
You are here
Related Resources
Dec 12, 2024 in Cybersecurity, in Federal & State Resources, in Security Preparedness
Dec 12, 2024 in Cybersecurity, in OT-ICS Security, in Security Preparedness
Dec 12, 2024 in Cybersecurity, in OT-ICS Security, in Federal & State Resources