← Voltar para CVEs
CVE-2014-5427
N/ADescricao
Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote attackers to read password hashes via a POST request.
Detalhes CVE
Pontuacao CVSS v3.1N/A
Publicado3/29/2015
Ultima modificacao4/12/2025
Fontenvd
Avistamentos honeypot0
Produtos afetados
johnsoncontrols:application_and_data_serverjohnsoncontrols:extended_application_and_data_serverjohnsoncontrols:lonworks_control_server_lcs8520johnsoncontrols:metsysjohnsoncontrols:network_automation_engine_5510-2johnsoncontrols:network_automation_engine_5510-2ujohnsoncontrols:network_automation_engine_5511-2johnsoncontrols:network_automation_engine_5520-2johnsoncontrols:network_automation_engine_5521-2johnsoncontrols:network_integration_engine_5510-2johnsoncontrols:network_integration_engine_5511-2johnsoncontrols:nxe8500
Fraquezas (CWE)
CWE-200
Referencias
https://ics-cert.us-cert.gov/advisories/ICSA-14-350-02(ics-cert@hq.dhs.gov)
https://ics-cert.us-cert.gov/advisories/ICSA-14-350-02(af854a3a-2127-422b-91ae-364da2661108)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.