5
CVSSv2

CVE-2014-5427

Published: 29/03/2015 Updated: 30/03/2015
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Johnson Controls Metasys 4.1 up to and including 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote malicious users to read password hashes via a POST request.

Vulnerable Product Search on Vulmon Subscribe to Product

johnsoncontrols metsys 4.1

johnsoncontrols metsys 6.5