CVE-2023-4486

Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC engines prior to versions 11.0.6 and 12.0.4 and Facility Explorer F4-SNC engines prior to versions 11.0.6 and 12.0.4 to cause denial-of-service.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:johnsoncontrols:nae55_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:nae55:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:johnsoncontrols:sne22000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:sne22000:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:johnsoncontrols:sne11000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:sne11000:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:johnsoncontrols:sne10500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:sne10500:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:johnsoncontrols:sne110l0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:sne110l0:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:johnsoncontrols:snc25150-0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:snc25150-0:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:johnsoncontrols:snc25150-04_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:snc25150-04:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:johnsoncontrols:snc16120-0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:snc16120-0:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:johnsoncontrols:snc16120-04_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:snc16120-04:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:f4-snc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:f4-snc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:f4-snc:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-12-07 20:15

Updated : 2023-12-19 17:15


NVD link : CVE-2023-4486

Mitre link : CVE-2023-4486

CVE.ORG link : CVE-2023-4486


JSON object : View

Products Affected

johnsoncontrols

  • sne11000
  • snc16120-0
  • sne22000_firmware
  • snc25150-0
  • snc25150-04
  • sne22000
  • sne110l0_firmware
  • nae55
  • snc16120-04
  • sne10500
  • snc25150-0_firmware
  • f4-snc_firmware
  • snc25150-04_firmware
  • nae55_firmware
  • sne10500_firmware
  • f4-snc
  • sne11000_firmware
  • snc16120-0_firmware
  • sne110l0
  • snc16120-04_firmware
CWE
CWE-770

Allocation of Resources Without Limits or Throttling

CWE-400

Uncontrolled Resource Consumption