CVE-2014-5427
 
Severity Score
7.5
*CVSS v3
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote attackers to read password hashes via a POST request.
Johnson Controls Metasys 4.1 hasta 6.5, utilizado en Application and Data Server (ADS), Extended Application and Data Server (también conocido como ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, y NxE8500, permite a atacantes remotos leer los hashes de contraseñas a través de una solicitud POST.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2014-08-22 CVE Reserved
- 2015-03-29 CVE Published
- 2024-08-06 CVE Updated
- 2024-12-17 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (1)
URL | Tag | Source |
---|---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-14-350-02 | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 4.1 Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Application And Data Server Search vendor "Johnsoncontrols" for product "Application And Data Server" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 4.1 Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Extended Application And Data Server Search vendor "Johnsoncontrols" for product "Extended Application And Data Server" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 4.1 Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Lonworks Control Server Lcs8520 Search vendor "Johnsoncontrols" for product "Lonworks Control Server Lcs8520" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 4.1 Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Network Automation Engine 5510-2 Search vendor "Johnsoncontrols" for product "Network Automation Engine 5510-2" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 4.1 Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Network Automation Engine 5510-2u Search vendor "Johnsoncontrols" for product "Network Automation Engine 5510-2u" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 4.1 Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Network Automation Engine 5511-2 Search vendor "Johnsoncontrols" for product "Network Automation Engine 5511-2" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 4.1 Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Network Automation Engine 5520-2 Search vendor "Johnsoncontrols" for product "Network Automation Engine 5520-2" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 4.1 Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Network Automation Engine 5521-2 Search vendor "Johnsoncontrols" for product "Network Automation Engine 5521-2" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 4.1 Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Network Integration Engine 5510-2 Search vendor "Johnsoncontrols" for product "Network Integration Engine 5510-2" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 4.1 Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Network Integration Engine 5511-2 Search vendor "Johnsoncontrols" for product "Network Integration Engine 5511-2" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 4.1 Search vendor "Johnsoncontrols" for product "Metsys" and version "4.1" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Nxe8500 Search vendor "Johnsoncontrols" for product "Nxe8500" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 6.5 Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Application And Data Server Search vendor "Johnsoncontrols" for product "Application And Data Server" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 6.5 Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Extended Application And Data Server Search vendor "Johnsoncontrols" for product "Extended Application And Data Server" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 6.5 Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Lonworks Control Server Lcs8520 Search vendor "Johnsoncontrols" for product "Lonworks Control Server Lcs8520" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 6.5 Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Network Automation Engine 5510-2 Search vendor "Johnsoncontrols" for product "Network Automation Engine 5510-2" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 6.5 Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Network Automation Engine 5510-2u Search vendor "Johnsoncontrols" for product "Network Automation Engine 5510-2u" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 6.5 Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Network Automation Engine 5511-2 Search vendor "Johnsoncontrols" for product "Network Automation Engine 5511-2" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 6.5 Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Network Automation Engine 5520-2 Search vendor "Johnsoncontrols" for product "Network Automation Engine 5520-2" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 6.5 Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Network Automation Engine 5521-2 Search vendor "Johnsoncontrols" for product "Network Automation Engine 5521-2" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 6.5 Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Network Integration Engine 5510-2 Search vendor "Johnsoncontrols" for product "Network Integration Engine 5510-2" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 6.5 Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Network Integration Engine 5511-2 Search vendor "Johnsoncontrols" for product "Network Integration Engine 5511-2" | - | - |
Safe
|
Johnsoncontrols Search vendor "Johnsoncontrols" | Metsys Search vendor "Johnsoncontrols" for product "Metsys" | 6.5 Search vendor "Johnsoncontrols" for product "Metsys" and version "6.5" | - |
Affected
| in | Johnsoncontrols Search vendor "Johnsoncontrols" | Nxe8500 Search vendor "Johnsoncontrols" for product "Nxe8500" | - | - |
Safe
|