# Johnson Controls Metasys Vulnerabilities Expose Building Automation Systems to Remote Attack


## The Threat


Johnson Controls' Metasys platform sits at the nerve center of building operations in thousands of hospitals, government facilities, data centers, and commercial properties worldwide. It manages HVAC, access control, fire suppression, and energy systems — the kind of infrastructure that, when disrupted, doesn't just cause inconvenience but can endanger lives and violate regulatory requirements. When CISA issues an advisory against Metasys, the blast radius is measured in building portfolios, not individual systems.


The vulnerabilities disclosed in this advisory affect multiple components of the Metasys ecosystem, including the Site Director, server software, and associated tooling. Attackers exploiting these flaws could gain unauthorized access to building management interfaces, manipulate environmental controls, exfiltrate configuration data, or pivot deeper into enterprise networks — many of which use building automation systems as a trusted, under-monitored segment.


What makes Metasys exposure particularly dangerous is the deployment context. Building automation systems are routinely connected to corporate IT networks for monitoring and remote management, yet they are rarely subject to the same security scrutiny as IT infrastructure. Patch cycles are slow, network segmentation is often inadequate, and many installations run versions that are years behind current releases.


## Severity and Impact


| Field | Details |

|---|---|

| CVE | See CISA advisory (node/25304) |

| CVSS Score | Up to 8.6 (High) |

| Attack Vector | Network |

| Attack Complexity | Low |

| Privileges Required | None / Low (varies by CVE) |

| User Interaction | None |

| Scope | Unchanged |

| CWE | CWE-22 (Path Traversal), CWE-79 (XSS), CWE-319 (Cleartext Transmission), CWE-307 (Brute Force) |

| Advisory | CISA ICS Advisory |

| Vendor | Johnson Controls |


The combination of a network-accessible attack vector, low attack complexity, and no authentication requirement on certain flaws makes exploitation realistic for a moderately skilled attacker with network access to the target system.


## Affected Products


The following Metasys components are confirmed affected:


Metasys Server / ADS / ADX

  • All versions prior to the patched release (see vendor bulletin for specific version strings)

  • Metasys Site Controller (SC, SCT, SCT Pro)

  • Legacy and current generation variants

  • Metasys NAE/NIE/NCE Engines

  • Network Automation Engines running unpatched firmware

  • Metasys Open Data Server (ODS)

  • Versions exposed to local network access

  • JCI Companion Tools

  • LonMaker integration tool
  • JCI Site Director

  • Check the Johnson Controls Product Security Advisory Portal for the exact version matrix; the affected range spans multiple major release lines.


    ## Mitigations


    Immediate steps:


  • Apply vendor patches. Johnson Controls has released updated firmware and software addressing the disclosed vulnerabilities. Patch as quickly as operational constraints allow — BAS patch windows often require coordination with facilities management, so schedule them now rather than waiting.

  • Restrict network access. Metasys servers and engines should not be directly reachable from general corporate networks or the internet. Place BAS infrastructure behind a dedicated firewall segment with deny-by-default rules. Only permit management traffic from authenticated jump hosts.

  • Disable remote access features when not in use. Many Metasys deployments have web-based UI or API endpoints exposed for convenience. Disable or restrict these unless actively needed.

  • Audit authentication configurations. Review whether any Metasys interfaces allow anonymous access or use default credentials. Johnson Controls has a known history of factory-default credential issues in legacy deployments.

  • Enable logging and monitoring. Forward Metasys logs to your SIEM if not already configured. Look for unusual authentication attempts, unexpected API calls, or configuration changes made outside maintenance windows.

  • Segment OT from IT. If Metasys systems are currently on the same VLAN or subnet as office or datacenter infrastructure, prioritize network redesign. Even a simple ACL at the distribution layer significantly limits lateral movement potential.

  • For organizations that cannot patch immediately, CISA recommends minimizing network exposure for all control system devices, using VPN for remote access (ensuring VPNs are themselves patched), and performing impact analysis before deploying any defensive measures in live building environments.


    ## References


  • [CISA ICS Advisory — Johnson Controls Metasys](https://www.cisa.gov/news-events/ics-advisories/)
  • [Johnson Controls Product Security](https://www.johnsoncontrols.com/cyber-solutions/security-advisories)
  • [CISA ICS-CERT Advisories Portal](https://www.cisa.gov/ics)

  • ---


    ## HackWire Analysis


    The Johnson Controls Metasys advisory deserves more attention than it typically gets, and here's why: building automation systems represent one of the largest attack surfaces in operational technology that almost nobody talks about.


    Every major hospital network, federal building, and Fortune 500 headquarters runs some form of BAS. Metasys alone claims to manage over 500 million square feet of building space globally. The security posture of these systems lags a decade behind IT — not because operators are careless, but because the operational constraints are genuinely different. You cannot patch a hospital HVAC controller during a heatwave. You cannot take down access control systems while buildings are occupied. The result is a sprawling installed base running software that was never designed for the threat environment it now inhabits.


    The network-accessible, low-complexity nature of these vulnerabilities is the real story. Attackers don't need to be on-site; they need a path to the Metasys interface, which in many enterprise environments means compromising a single endpoint on a corporate network that has flat routing to the BAS segment. From there, manipulating temperature setpoints, unlocking doors, or disrupting fire suppression coordination becomes plausible — and in hospital or data center contexts, the consequences are not theoretical.


    Security teams should treat this advisory as a forcing function to audit whether BAS infrastructure appears in their asset inventory at all. In many organizations, building systems were installed by facilities contractors who handed over credentials to facilities staff, and IT security has no visibility whatsoever. If you don't know what Metasys versions you're running, that's the actual vulnerability.


    The pattern here — another ICS/BAS advisory against a dominant market player — fits a broader shift. OT and BAS security has been on CISA's radar since the Oldsmar water treatment incident in 2021 made clear that physical infrastructure systems connected to IP networks are legitimate targets. Expect more advisories at this frequency, and plan patching programs accordingly.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Policy](https://www.hackwire.news/category/policy) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)