CVE-2023-4486

Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC engines prior to versions 11.0.6 and 12.0.4 and Facility Explorer F4-SNC engines prior to versions 11.0.6 and 12.0.4 to cause denial-of-service.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:johnsoncontrols:nae55_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:nae55:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:johnsoncontrols:sne22000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:sne22000:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:johnsoncontrols:sne11000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:sne11000:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:johnsoncontrols:sne10500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:sne10500:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:johnsoncontrols:sne110l0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:sne110l0:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:johnsoncontrols:snc25150-0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:snc25150-0:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:johnsoncontrols:snc25150-04_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:snc25150-04:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:johnsoncontrols:snc16120-0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:snc16120-0:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:johnsoncontrols:snc16120-04_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:snc16120-04:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:f4-snc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:f4-snc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:f4-snc:-:*:*:*:*:*:*:*

History

19 Dec 2023, 17:15

Type Values Removed Values Added
Summary Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC engines prior to version 12.0.4 and Facility Explorer F4-SNC engines prior to versions 11.0.6 and 12.0.4 to cause denial-of-service. Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC engines prior to versions 11.0.6 and 12.0.4 and Facility Explorer F4-SNC engines prior to versions 11.0.6 and 12.0.4 to cause denial-of-service.

13 Dec 2023, 18:47

Type Values Removed Values Added
CWE CWE-770
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References () https://www.cisa.gov/news-events/ics-advisories/icsa-23-341-03 - () https://www.cisa.gov/news-events/ics-advisories/icsa-23-341-03 - Third Party Advisory, US Government Resource
References () https://www.johnsoncontrols.com/cyber-solutions/security-advisories - () https://www.johnsoncontrols.com/cyber-solutions/security-advisories - Vendor Advisory
CPE cpe:2.3:o:johnsoncontrols:sne22000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:sne10500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:sne22000:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:snc25150-04_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:sne110l0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:sne11000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:sne110l0:-:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:f4-snc:-:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:sne10500:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:nae55_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:snc16120-0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:sne11000:-:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:snc25150-0:-:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:snc25150-04:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:snc16120-04_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:snc16120-0:-:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:snc16120-04:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:snc25150-0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:f4-snc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:nae55:-:*:*:*:*:*:*:*
First Time Johnsoncontrols snc16120-0 Firmware
Johnsoncontrols nae55
Johnsoncontrols sne110l0
Johnsoncontrols
Johnsoncontrols nae55 Firmware
Johnsoncontrols sne11000 Firmware
Johnsoncontrols snc16120-04 Firmware
Johnsoncontrols snc25150-04
Johnsoncontrols snc25150-04 Firmware
Johnsoncontrols snc25150-0
Johnsoncontrols sne10500
Johnsoncontrols snc25150-0 Firmware
Johnsoncontrols sne22000 Firmware
Johnsoncontrols snc16120-0
Johnsoncontrols snc16120-04
Johnsoncontrols sne10500 Firmware
Johnsoncontrols sne22000
Johnsoncontrols f4-snc Firmware
Johnsoncontrols f4-snc
Johnsoncontrols sne110l0 Firmware
Johnsoncontrols sne11000

07 Dec 2023, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-07 20:15

Updated : 2023-12-19 17:15


NVD link : CVE-2023-4486

Mitre link : CVE-2023-4486


JSON object : View

Products Affected

johnsoncontrols

  • sne11000
  • sne10500
  • snc16120-04_firmware
  • sne22000
  • nae55_firmware
  • sne110l0_firmware
  • snc16120-0
  • sne110l0
  • snc25150-0_firmware
  • nae55
  • snc16120-0_firmware
  • sne10500_firmware
  • sne11000_firmware
  • snc16120-04
  • sne22000_firmware
  • snc25150-04_firmware
  • snc25150-0
  • f4-snc
  • snc25150-04
  • f4-snc_firmware
CWE
CWE-770

Allocation of Resources Without Limits or Throttling