← Retour aux CVEs
CVE-2014-5427
N/ADescription
Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote attackers to read password hashes via a POST request.
Details CVE
Score CVSS v3.1N/A
Publie3/29/2015
Derniere modification4/12/2025
Sourcenvd
Observations honeypot0
Produits affectes
johnsoncontrols:application_and_data_serverjohnsoncontrols:extended_application_and_data_serverjohnsoncontrols:lonworks_control_server_lcs8520johnsoncontrols:metsysjohnsoncontrols:network_automation_engine_5510-2johnsoncontrols:network_automation_engine_5510-2ujohnsoncontrols:network_automation_engine_5511-2johnsoncontrols:network_automation_engine_5520-2johnsoncontrols:network_automation_engine_5521-2johnsoncontrols:network_integration_engine_5510-2johnsoncontrols:network_integration_engine_5511-2johnsoncontrols:nxe8500
Faiblesses (CWE)
CWE-200
References
https://ics-cert.us-cert.gov/advisories/ICSA-14-350-02(ics-cert@hq.dhs.gov)
https://ics-cert.us-cert.gov/advisories/ICSA-14-350-02(af854a3a-2127-422b-91ae-364da2661108)
Correlations IOC
Aucune correlation enregistree
This product uses data from the NVD API but is not endorsed or certified by the NVD.