Vulnerabilities > Johnsoncontrols > Application AND Data Server

DATE CVE VULNERABILITY TITLE RISK
2015-03-29 CVE-2014-5428 Unspecified vulnerability in Johnsoncontrols Metsys 4.1/6.5
Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote attackers to execute arbitrary code by uploading a shell script.
network
low complexity
johnsoncontrols
critical
10.0
2015-03-29 CVE-2014-5427 Information Exposure vulnerability in Johnsoncontrols Metsys 4.1/6.5
Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote attackers to read password hashes via a POST request.
network
low complexity
johnsoncontrols CWE-200
5.0