# Johnson Controls Metasys Vulnerabilities Expose Building Automation Systems to Remote Attack
## The Threat
Johnson Controls' Metasys platform sits at the nerve center of building operations in thousands of hospitals, government facilities, data centers, and commercial properties worldwide. It manages HVAC, access control, fire suppression, and energy systems — the kind of infrastructure that, when disrupted, doesn't just cause inconvenience but can endanger lives and violate regulatory requirements. When CISA issues an advisory against Metasys, the blast radius is measured in building portfolios, not individual systems.
The vulnerabilities disclosed in this advisory affect multiple components of the Metasys ecosystem, including the Site Director, server software, and associated tooling. Attackers exploiting these flaws could gain unauthorized access to building management interfaces, manipulate environmental controls, exfiltrate configuration data, or pivot deeper into enterprise networks — many of which use building automation systems as a trusted, under-monitored segment.
What makes Metasys exposure particularly dangerous is the deployment context. Building automation systems are routinely connected to corporate IT networks for monitoring and remote management, yet they are rarely subject to the same security scrutiny as IT infrastructure. Patch cycles are slow, network segmentation is often inadequate, and many installations run versions that are years behind current releases.
## Severity and Impact
| Field | Details |
|---|---|
| CVE | See CISA advisory (node/25304) |
| CVSS Score | Up to 8.6 (High) |
| Attack Vector | Network |
| Attack Complexity | Low |
| Privileges Required | None / Low (varies by CVE) |
| User Interaction | None |
| Scope | Unchanged |
| CWE | CWE-22 (Path Traversal), CWE-79 (XSS), CWE-319 (Cleartext Transmission), CWE-307 (Brute Force) |
| Advisory | CISA ICS Advisory |
| Vendor | Johnson Controls |
The combination of a network-accessible attack vector, low attack complexity, and no authentication requirement on certain flaws makes exploitation realistic for a moderately skilled attacker with network access to the target system.
## Affected Products
The following Metasys components are confirmed affected:
Metasys Server / ADS / ADX
Metasys Site Controller (SC, SCT, SCT Pro)
Metasys NAE/NIE/NCE Engines
Metasys Open Data Server (ODS)
JCI Companion Tools
Check the Johnson Controls Product Security Advisory Portal for the exact version matrix; the affected range spans multiple major release lines.
## Mitigations
Immediate steps:
For organizations that cannot patch immediately, CISA recommends minimizing network exposure for all control system devices, using VPN for remote access (ensuring VPNs are themselves patched), and performing impact analysis before deploying any defensive measures in live building environments.
## References
---
## HackWire Analysis
The Johnson Controls Metasys advisory deserves more attention than it typically gets, and here's why: building automation systems represent one of the largest attack surfaces in operational technology that almost nobody talks about.
Every major hospital network, federal building, and Fortune 500 headquarters runs some form of BAS. Metasys alone claims to manage over 500 million square feet of building space globally. The security posture of these systems lags a decade behind IT — not because operators are careless, but because the operational constraints are genuinely different. You cannot patch a hospital HVAC controller during a heatwave. You cannot take down access control systems while buildings are occupied. The result is a sprawling installed base running software that was never designed for the threat environment it now inhabits.
The network-accessible, low-complexity nature of these vulnerabilities is the real story. Attackers don't need to be on-site; they need a path to the Metasys interface, which in many enterprise environments means compromising a single endpoint on a corporate network that has flat routing to the BAS segment. From there, manipulating temperature setpoints, unlocking doors, or disrupting fire suppression coordination becomes plausible — and in hospital or data center contexts, the consequences are not theoretical.
Security teams should treat this advisory as a forcing function to audit whether BAS infrastructure appears in their asset inventory at all. In many organizations, building systems were installed by facilities contractors who handed over credentials to facilities staff, and IT security has no visibility whatsoever. If you don't know what Metasys versions you're running, that's the actual vulnerability.
The pattern here — another ICS/BAS advisory against a dominant market player — fits a broader shift. OT and BAS security has been on CISA's radar since the Oldsmar water treatment incident in 2021 made clear that physical infrastructure systems connected to IP networks are legitimate targets. Expect more advisories at this frequency, and plan patching programs accordingly.
— HackWire Editorial
---
## Related Coverage