CVE-2014-5427
Summary
| CVE | CVE-2014-5427 |
|---|---|
| State | PUBLISHED |
| Assigner | icscert |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2015-03-29 10:59:00 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote attackers to read password hashes via a POST request. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Johnsoncontrols | Application And Data Server | - | All | All | All |
| Hardware | Johnsoncontrols | Extended Application And Data Server | - | All | All | All |
| Hardware | Johnsoncontrols | Lonworks Control Server Lcs8520 | - | All | All | All |
| Application | Johnsoncontrols | Metsys | 4.1 | All | All | All |
| Application | Johnsoncontrols | Metsys | 6.5 | All | All | All |
| Hardware | Johnsoncontrols | Network Automation Engine 5510-2 | - | All | All | All |
| Hardware | Johnsoncontrols | Network Automation Engine 5510-2u | - | All | All | All |
| Hardware | Johnsoncontrols | Network Automation Engine 5511-2 | - | All | All | All |
| Hardware | Johnsoncontrols | Network Automation Engine 5520-2 | - | All | All | All |
| Hardware | Johnsoncontrols | Network Automation Engine 5521-2 | - | All | All | All |
| Hardware | Johnsoncontrols | Network Integration Engine 5510-2 | - | All | All | All |
| Hardware | Johnsoncontrols | Network Integration Engine 5511-2 | - | All | All | All |
| Hardware | Johnsoncontrols | Nxe8500 | - | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Johnson Controls Metasys Vulnerabilities | ICS-CERT | af854a3a-2127-422b-91ae-364da2661108 | ics-cert.us-cert.gov | Third Party Advisory, US Government Resource |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.