CVE-2023-4486

Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC engines prior to versions 11.0.6 and 12.0.4 and Facility Explorer F4-SNC engines prior to versions 11.0.6 and 12.0.4 to cause denial-of-service.
References
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:johnsoncontrols:nae55_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:nae55:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
cpe:2.3:o:johnsoncontrols:sne22000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:sne22000:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
cpe:2.3:o:johnsoncontrols:sne11000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:sne11000:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
cpe:2.3:o:johnsoncontrols:sne10500_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:sne10500:-:*:*:*:*:*:*:*

Configuration 5 (hide)

AND
cpe:2.3:o:johnsoncontrols:sne110l0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:sne110l0:-:*:*:*:*:*:*:*

Configuration 6 (hide)

AND
cpe:2.3:o:johnsoncontrols:snc25150-0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:snc25150-0:-:*:*:*:*:*:*:*

Configuration 7 (hide)

AND
cpe:2.3:o:johnsoncontrols:snc25150-04_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:snc25150-04:-:*:*:*:*:*:*:*

Configuration 8 (hide)

AND
cpe:2.3:o:johnsoncontrols:snc16120-0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:snc16120-0:-:*:*:*:*:*:*:*

Configuration 9 (hide)

AND
cpe:2.3:o:johnsoncontrols:snc16120-04_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:snc16120-04:-:*:*:*:*:*:*:*

Configuration 10 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:f4-snc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:f4-snc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:f4-snc:-:*:*:*:*:*:*:*

History

19 Dec 2023, 17:15

Type Values Removed Values Added
Summary Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC engines prior to version 12.0.4 and Facility Explorer F4-SNC engines prior to versions 11.0.6 and 12.0.4 to cause denial-of-service. Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC engines prior to versions 11.0.6 and 12.0.4 and Facility Explorer F4-SNC engines prior to versions 11.0.6 and 12.0.4 to cause denial-of-service.

13 Dec 2023, 18:47

Type Values Removed Values Added
CPE cpe:2.3:h:johnsoncontrols:sne22000:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:nae55_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:sne10500:-:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:sne110l0:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:snc25150-04_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:snc25150-0:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:snc25150-0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:f4-snc_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:snc16120-04_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:sne22000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:snc16120-0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:sne11000_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:sne110l0_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:f4-snc:-:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:snc16120-04:-:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:sne11000:-:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:snc16120-0:-:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:nae55:-:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:snc25150-04:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:sne10500_firmware:*:*:*:*:*:*:*:*
References () https://www.cisa.gov/news-events/ics-advisories/icsa-23-341-03 - () https://www.cisa.gov/news-events/ics-advisories/icsa-23-341-03 - Third Party Advisory, US Government Resource
References () https://www.johnsoncontrols.com/cyber-solutions/security-advisories - () https://www.johnsoncontrols.com/cyber-solutions/security-advisories - Vendor Advisory
CWE CWE-770
First Time Johnsoncontrols sne22000
Johnsoncontrols snc25150-0 Firmware
Johnsoncontrols f4-snc Firmware
Johnsoncontrols snc25150-04
Johnsoncontrols snc25150-04 Firmware
Johnsoncontrols sne10500
Johnsoncontrols sne11000
Johnsoncontrols snc16120-0 Firmware
Johnsoncontrols f4-snc
Johnsoncontrols snc16120-04
Johnsoncontrols sne22000 Firmware
Johnsoncontrols nae55
Johnsoncontrols
Johnsoncontrols sne10500 Firmware
Johnsoncontrols snc16120-0
Johnsoncontrols sne11000 Firmware
Johnsoncontrols nae55 Firmware
Johnsoncontrols snc25150-0
Johnsoncontrols snc16120-04 Firmware
Johnsoncontrols sne110l0 Firmware
Johnsoncontrols sne110l0
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5

07 Dec 2023, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-12-07 20:15

Updated : 2024-02-28 20:54


NVD link : CVE-2023-4486

Mitre link : CVE-2023-4486

CVE.ORG link : CVE-2023-4486


JSON object : View

Products Affected

johnsoncontrols

  • snc16120-0
  • f4-snc_firmware
  • sne110l0_firmware
  • sne10500_firmware
  • sne11000
  • f4-snc
  • sne10500
  • snc16120-04
  • sne11000_firmware
  • snc16120-0_firmware
  • snc16120-04_firmware
  • sne22000_firmware
  • sne110l0
  • snc25150-0
  • snc25150-04
  • snc25150-04_firmware
  • sne22000
  • nae55_firmware
  • snc25150-0_firmware
  • nae55
CWE
CWE-770

Allocation of Resources Without Limits or Throttling

CWE-400

Uncontrolled Resource Consumption