Vulnerabilities > Johnsoncontrols

DATE CVE VULNERABILITY TITLE RISK
2015-03-29 CVE-2014-5428 Unspecified vulnerability in Johnsoncontrols Metsys 4.1/6.5
Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote attackers to execute arbitrary code by uploading a shell script.
network
low complexity
johnsoncontrols
critical
10.0
2015-03-29 CVE-2014-5427 Information Exposure vulnerability in Johnsoncontrols Metsys 4.1/6.5
Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote attackers to read password hashes via a POST request.
network
low complexity
johnsoncontrols CWE-200
5.0
2012-07-16 CVE-2012-4026 Improper Input Validation vulnerability in Johnsoncontrols products
The Johnson Controls Pegasys P2000 server with software before 3.11 allows remote attackers to trigger false alerts via crafted packets to TCP port 41013 (aka the upload port), a different vulnerability than CVE-2012-2607.
network
low complexity
johnsoncontrols CWE-20
5.0
2012-07-16 CVE-2012-2607 OS Command Injection vulnerability in Johnsoncontrols Network Controller and Network Controller Firmware
The Johnson Controls CK721-A controller with firmware before SSM4388_03.1.0.14_BB allows remote attackers to perform arbitrary actions via crafted packets to TCP port 41014 (aka the download port).
network
low complexity
johnsoncontrols CWE-78
7.5