// For flags

CVE-2014-5427

 

Severity Score

7.5
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote attackers to read password hashes via a POST request.

Johnson Controls Metasys 4.1 hasta 6.5, utilizado en Application and Data Server (ADS), Extended Application and Data Server (también conocido como ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, y NxE8500, permite a atacantes remotos leer los hashes de contraseñas a través de una solicitud POST.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2014-08-22 CVE Reserved
  • 2015-03-29 CVE Published
  • 2024-08-06 CVE Updated
  • 2024-12-17 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (1)
URL Date SRC
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
4.1
Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Application And Data Server
Search vendor "Johnsoncontrols" for product "Application And Data Server"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
4.1
Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Extended Application And Data Server
Search vendor "Johnsoncontrols" for product "Extended Application And Data Server"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
4.1
Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Lonworks Control Server Lcs8520
Search vendor "Johnsoncontrols" for product "Lonworks Control Server Lcs8520"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
4.1
Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Network Automation Engine 5510-2
Search vendor "Johnsoncontrols" for product "Network Automation Engine 5510-2"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
4.1
Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Network Automation Engine 5510-2u
Search vendor "Johnsoncontrols" for product "Network Automation Engine 5510-2u"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
4.1
Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Network Automation Engine 5511-2
Search vendor "Johnsoncontrols" for product "Network Automation Engine 5511-2"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
4.1
Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Network Automation Engine 5520-2
Search vendor "Johnsoncontrols" for product "Network Automation Engine 5520-2"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
4.1
Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Network Automation Engine 5521-2
Search vendor "Johnsoncontrols" for product "Network Automation Engine 5521-2"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
4.1
Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Network Integration Engine 5510-2
Search vendor "Johnsoncontrols" for product "Network Integration Engine 5510-2"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
4.1
Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Network Integration Engine 5511-2
Search vendor "Johnsoncontrols" for product "Network Integration Engine 5511-2"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
4.1
Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Nxe8500
Search vendor "Johnsoncontrols" for product "Nxe8500"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
6.5
Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Application And Data Server
Search vendor "Johnsoncontrols" for product "Application And Data Server"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
6.5
Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Extended Application And Data Server
Search vendor "Johnsoncontrols" for product "Extended Application And Data Server"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
6.5
Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Lonworks Control Server Lcs8520
Search vendor "Johnsoncontrols" for product "Lonworks Control Server Lcs8520"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
6.5
Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Network Automation Engine 5510-2
Search vendor "Johnsoncontrols" for product "Network Automation Engine 5510-2"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
6.5
Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Network Automation Engine 5510-2u
Search vendor "Johnsoncontrols" for product "Network Automation Engine 5510-2u"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
6.5
Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Network Automation Engine 5511-2
Search vendor "Johnsoncontrols" for product "Network Automation Engine 5511-2"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
6.5
Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Network Automation Engine 5520-2
Search vendor "Johnsoncontrols" for product "Network Automation Engine 5520-2"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
6.5
Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Network Automation Engine 5521-2
Search vendor "Johnsoncontrols" for product "Network Automation Engine 5521-2"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
6.5
Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Network Integration Engine 5510-2
Search vendor "Johnsoncontrols" for product "Network Integration Engine 5510-2"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
6.5
Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Network Integration Engine 5511-2
Search vendor "Johnsoncontrols" for product "Network Integration Engine 5511-2"
--
Safe
Johnsoncontrols
Search vendor "Johnsoncontrols"
Metsys
Search vendor "Johnsoncontrols" for product "Metsys"
6.5
Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5"
-
Affected
in Johnsoncontrols
Search vendor "Johnsoncontrols"
Nxe8500
Search vendor "Johnsoncontrols" for product "Nxe8500"
--
Safe