CVE-2014-5427
Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote attackers to read password hashes via a POST request.
Published:Mar 29, 2015
Last Modified:Apr 12, 2025
EPS:Mar 29, 2015
EPSS Score:0.00533
CVSS Score:5
Affected Products
Vendor
Product
Action
Vendor
Johnsoncontrols
Product
Application And Data Server
Johnsoncontrols
Application And Data Server
Vendor
Johnsoncontrols
Product
Extended Application And Data Server
Johnsoncontrols
Extended Application And Data Server
Vendor
Johnsoncontrols
Product
Lonworks Control Server Lcs8520
Johnsoncontrols
Lonworks Control Server Lcs8520
Vendor
Johnsoncontrols
Product
Metsys
Johnsoncontrols
Metsys
Vendor
Johnsoncontrols
Product
Network Automation Engine 5510-2
Johnsoncontrols
Network Automation Engine 5510-2
Vendor
Johnsoncontrols
Product
Network Automation Engine 5510-2u
Johnsoncontrols
Network Automation Engine 5510-2u
Vendor
Johnsoncontrols
Product
Network Automation Engine 5511-2
Johnsoncontrols
Network Automation Engine 5511-2
Vendor
Johnsoncontrols
Product
Network Automation Engine 5520-2
Johnsoncontrols
Network Automation Engine 5520-2
Vendor
Johnsoncontrols
Product
Network Automation Engine 5521-2
Johnsoncontrols
Network Automation Engine 5521-2
Vendor
Johnsoncontrols
Product
Network Integration Engine 5510-2
Johnsoncontrols
Network Integration Engine 5510-2
Vendor
Johnsoncontrols
Product
Network Integration Engine 5511-2
Johnsoncontrols
Network Integration Engine 5511-2
Vendor
Johnsoncontrols
Product
Nxe8500
Johnsoncontrols
Nxe8500
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
