Metasys® ADS/ADX servers and NAE/NIE/NCE engines prior to 9.0 make use of a shared RSA key pair for certain encryption operations involving the Site Management Portal (SMP).
Solution:
Nonces should be used for the present occasion and only once.
The product contains hard-coded credentials, such as a password or cryptographic key.
Link | Tags |
---|---|
https://www.johnsoncontrols.com/-/media/jci/cyber-solutions/product-security-advisories/2019/jci-psa-2019-06-v1-metasys-icsa-19-227-01.pdf | vendor advisory |
https://www.us-cert.gov/ics/advisories/icsa-19-227-01 | mitigation third party advisory us government resource |