CVE Feed

    Dashboard / CVE / CVE-2023-4486

    CVE-2023-4486

    Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC engines prior to versions 11.0.6 and 12.0.4 and Facility Explorer F4-SNC engines prior to versions 11.0.6 and 12.0.4 to cause denial-of-service.

    Published:Dec 7, 2023
    Last Modified:May 28, 2025
    EPS:Dec 7, 2023
    EPSS Score:0.00131
    CVSS Score:7.5

    Affected Products

    Vendor
    Johnsoncontrols
    Product
    F4-snc
    Vendor
    Johnsoncontrols
    Product
    F4-snc Firmware
    Vendor
    Johnsoncontrols
    Product
    Nae55
    Vendor
    Johnsoncontrols
    Product
    Nae55 Firmware
    Vendor
    Johnsoncontrols
    Product
    Snc16120-0
    Vendor
    Johnsoncontrols
    Product
    Snc16120-04
    Vendor
    Johnsoncontrols
    Product
    Snc16120-04 Firmware
    Vendor
    Johnsoncontrols
    Product
    Snc16120-0 Firmware
    Vendor
    Johnsoncontrols
    Product
    Snc25150-0
    Vendor
    Johnsoncontrols
    Product
    Snc25150-04
    Vendor
    Johnsoncontrols
    Product
    Snc25150-04 Firmware
    Vendor
    Johnsoncontrols
    Product
    Snc25150-0 Firmware
    Vendor
    Johnsoncontrols
    Product
    Sne10500
    Vendor
    Johnsoncontrols
    Product
    Sne10500 Firmware
    Vendor
    Johnsoncontrols
    Product
    Sne11000
    Vendor
    Johnsoncontrols
    Product
    Sne11000 Firmware
    Vendor
    Johnsoncontrols
    Product
    Sne110l0
    Vendor
    Johnsoncontrols
    Product
    Sne110l0 Firmware
    Vendor
    Johnsoncontrols
    Product
    Sne22000
    Vendor
    Johnsoncontrols
    Product
    Sne22000 Firmware

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High