CVE-2023-4486

Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC engines prior to versions 11.0.6 and 12.0.4 and Facility Explorer F4-SNC engines prior to versions 11.0.6 and 12.0.4 to cause denial-of-service.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:johnsoncontrols:nae55_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:nae55:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:johnsoncontrols:sne22000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:sne22000:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:johnsoncontrols:sne11000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:sne11000:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:johnsoncontrols:sne10500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:sne10500:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:johnsoncontrols:sne110l0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:sne110l0:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:johnsoncontrols:snc25150-0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:snc25150-0:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:johnsoncontrols:snc25150-04_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:snc25150-04:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:johnsoncontrols:snc16120-0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:snc16120-0:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:johnsoncontrols:snc16120-04_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:snc16120-04:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:f4-snc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:f4-snc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:f4-snc:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:35

Type Values Removed Values Added
References () https://www.cisa.gov/news-events/ics-advisories/icsa-23-341-03 - Third Party Advisory, US Government Resource () https://www.cisa.gov/news-events/ics-advisories/icsa-23-341-03 - Third Party Advisory, US Government Resource
References () https://www.johnsoncontrols.com/cyber-solutions/security-advisories - Vendor Advisory () https://www.johnsoncontrols.com/cyber-solutions/security-advisories - Vendor Advisory

19 Dec 2023, 17:15

Type Values Removed Values Added
Summary Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC engines prior to version 12.0.4 and Facility Explorer F4-SNC engines prior to versions 11.0.6 and 12.0.4 to cause denial-of-service. Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC engines prior to versions 11.0.6 and 12.0.4 and Facility Explorer F4-SNC engines prior to versions 11.0.6 and 12.0.4 to cause denial-of-service.

13 Dec 2023, 18:47

Type Values Removed Values Added
CPE cpe:2.3:h:johnsoncontrols:snc25150-0:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:f4-snc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:snc25150-04:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:sne22000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:snc25150-0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:snc16120-04_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:sne10500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:sne110l0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:sne22000:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:snc16120-0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:sne11000:-:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:f4-snc:-:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:nae55:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:nae55_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:sne110l0:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:snc25150-04_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:sne10500:-:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:snc16120-04:-:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:snc16120-0:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:sne11000_firmware:*:*:*:*:*:*:*:*
First Time Johnsoncontrols sne10500 Firmware
Johnsoncontrols sne10500
Johnsoncontrols sne22000 Firmware
Johnsoncontrols
Johnsoncontrols snc16120-0
Johnsoncontrols sne110l0
Johnsoncontrols snc16120-04 Firmware
Johnsoncontrols sne11000 Firmware
Johnsoncontrols sne22000
Johnsoncontrols f4-snc Firmware
Johnsoncontrols snc25150-0 Firmware
Johnsoncontrols snc25150-0
Johnsoncontrols snc16120-0 Firmware
Johnsoncontrols snc25150-04
Johnsoncontrols snc25150-04 Firmware
Johnsoncontrols nae55 Firmware
Johnsoncontrols sne11000
Johnsoncontrols nae55
Johnsoncontrols snc16120-04
Johnsoncontrols f4-snc
Johnsoncontrols sne110l0 Firmware
References () https://www.cisa.gov/news-events/ics-advisories/icsa-23-341-03 - () https://www.cisa.gov/news-events/ics-advisories/icsa-23-341-03 - Third Party Advisory, US Government Resource
References () https://www.johnsoncontrols.com/cyber-solutions/security-advisories - () https://www.johnsoncontrols.com/cyber-solutions/security-advisories - Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CWE CWE-770

07 Dec 2023, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-07 20:15

Updated : 2024-11-21 08:35


NVD link : CVE-2023-4486

Mitre link : CVE-2023-4486

CVE.ORG link : CVE-2023-4486


JSON object : View

Products Affected

johnsoncontrols

  • sne22000_firmware
  • snc16120-0_firmware
  • sne11000_firmware
  • f4-snc_firmware
  • snc25150-04
  • nae55_firmware
  • sne22000
  • sne11000
  • sne10500
  • sne110l0_firmware
  • snc25150-04_firmware
  • snc16120-04_firmware
  • snc25150-0_firmware
  • snc16120-04
  • nae55
  • sne10500_firmware
  • f4-snc
  • snc25150-0
  • snc16120-0
  • sne110l0
CWE
CWE-400

Uncontrolled Resource Consumption

CWE-770

Allocation of Resources Without Limits or Throttling