SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2014-5428

Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network…

HIGH 10.0EPSS 3.87%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (3.87%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote attackers to execute arbitrary code by uploading a shell script.

CVSS 2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
3.87% probability · 90th percentile
CISA KEV
Not listed
Affected
johnsoncontrols/metsys
Source
ics-cert@hq.dhs.gov

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.