HIGH · 7.5

CVE-2023-4486

Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC engines prior to versions 11.0.6 and 12.0.4 and ...

Vulnerability Description

Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC engines prior to versions 11.0.6 and 12.0.4 and Facility Explorer F4-SNC engines prior to versions 11.0.6 and 12.0.4 to cause denial-of-service.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
JohnsoncontrolsNae55 Firmware< 12.0.4
JohnsoncontrolsNae55-
JohnsoncontrolsSne22000 Firmware< 12.0.4
JohnsoncontrolsSne22000-
JohnsoncontrolsSne11000 Firmware< 12.0.4
JohnsoncontrolsSne11000-
JohnsoncontrolsSne10500 Firmware< 12.0.4
JohnsoncontrolsSne10500-
JohnsoncontrolsSne110L0 Firmware< 12.0.4
JohnsoncontrolsSne110L0-
JohnsoncontrolsSnc25150-0 Firmware< 12.0.4
JohnsoncontrolsSnc25150-0-
JohnsoncontrolsSnc25150-04 Firmware< 12.0.4
JohnsoncontrolsSnc25150-04-
JohnsoncontrolsSnc16120-0 Firmware< 12.0.4
JohnsoncontrolsSnc16120-0-
JohnsoncontrolsSnc16120-04 Firmware< 12.0.4
JohnsoncontrolsSnc16120-04-
JohnsoncontrolsF4-Snc Firmware< 11.0.6
JohnsoncontrolsF4-Snc-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-4486?

CVE-2023-4486 is a vulnerability with a CVSS score of 7.5 (HIGH). Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC engines prior to versions 11.0.6 and 12.0.4 and ...

How severe is CVE-2023-4486?

CVE-2023-4486 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-4486?

Check the references section above for vendor advisories and patch information. Affected products include: Johnsoncontrols Nae55 Firmware, Johnsoncontrols Nae55, Johnsoncontrols Sne22000 Firmware, Johnsoncontrols Sne22000, Johnsoncontrols Sne11000 Firmware.