10
CVSSv2

CVE-2014-5428

Published: 29/03/2015 Updated: 30/03/2015
CVSS v2 Base Score: 10 | Impact Score: 10 | Exploitability Score: 10
VMScore: 890
Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 up to and including 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote malicious users to execute arbitrary code by uploading a shell script.

Vulnerable Product Search on Vulmon Subscribe to Product

johnsoncontrols metsys 4.1

johnsoncontrols metsys 6.5