Description
Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote attackers to read password hashes via a POST request.
Published: 2015-03-29
Score: 5.0 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2014-5315 Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote attackers to read password hashes via a POST request.
History

No history.

Subscriptions

Johnsoncontrols Application And Data Server Extended Application And Data Server Lonworks Control Server Lcs8520 Metsys Network Automation Engine 5510-2 Network Automation Engine 5510-2u Network Automation Engine 5511-2 Network Automation Engine 5520-2 Network Automation Engine 5521-2 Network Integration Engine 5510-2 Network Integration Engine 5511-2 Nxe8500
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-06T11:41:49.282Z

Reserved: 2014-08-22T00:00:00.000Z

Link: CVE-2014-5427

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2015-03-29T10:59:00.070

Modified: 2025-04-12T10:46:40.837

Link: CVE-2014-5427

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses