CVE-2014-5428
Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (a...
Affects 12 products across 1 vendor.
This vulnerability was disclosed in 2015. A critical vulnerability affects Johnsoncontrols systems (CVE-2014-5428). No public exploit code is currently available. Isolate affected systems if patching is not feasible.
BSID: BS-2015-GLOBAL-099483-C • Model: rule-based-v1 • Confidence: MEDIUM
Is this CVE in your environment?
BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.
Check My Environment →What is CVE-2014-5428?
What is the CVSS score for CVE-2014-5428?
Is CVE-2014-5428 actively exploited?
How do I remediate CVE-2014-5428?
What systems are affected by CVE-2014-5428?
| CVE ID | CVE-2014-5428 |
|---|---|
| BSID | BS-2015-GLOBAL-099483-C BreachSpider Global ID |
| CVSS Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| Published | 2015-03-29 |
| Last Modified | 2026-06-17 |
| ICS Relevance | 75% |
| Source | NVD |
Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote attackers to execute arbitrary code by uploading a shell script.
Source: NIST NVD / MITRE CVE Database
Vulnerability details: Unrestricted file upload vulnerability in unspecified web services in Johnson Controls Metasys 4.1 through 6.5, as used in Application and Data Server (ADS), Extended Application and Data Server (aka ADX), LonWorks Control Server 85 LCS8520, Network Automation Engine (NAE) 55xx-x, Network Integration Engine (NIE) 5xxx-x, and NxE8500, allows remote attackers to execute arbitrary code by uploading a shell script. CVSS vector: AV:N/AC:L/Au:N/C:C/I:C/A:C.
Exploitation Likelihood: LOW
| Vendor | Product | Affected Versions |
|---|---|---|
| Johnsoncontrols | Metsys | 4.1 6.5 |
| Johnsoncontrols | Application And Data Server | — |
| Johnsoncontrols | Extended Application And Data Server | — |
| Johnsoncontrols | Lonworks Control Server Lcs8520 | — |
| Johnsoncontrols | Network Automation Engine 5510-2 | — |
| Johnsoncontrols | Network Automation Engine 5510-2U | — |
| Johnsoncontrols | Network Automation Engine 5511-2 | — |
| Johnsoncontrols | Network Automation Engine 5520-2 | — |
| Johnsoncontrols | Network Automation Engine 5521-2 | — |
| Johnsoncontrols | Network Integration Engine 5510-2 | — |
| Johnsoncontrols | Network Integration Engine 5511-2 | — |
| Johnsoncontrols | Nxe8500 | — |
| CISA KEV | Not in KEV catalog |
|---|---|
| Public Exploit | Not confirmed |
| PoC Code | Not confirmed |
AI Enrichment Record — provenance & audit hash
| Model | rule-based-v1 |
|---|---|
| Confidence | MEDIUM |
| Enriched At | 2026-05-24 |
| SHA-512 Audit Hash | 5cc6f21a042c91bd9c92c27f17ca96c9497de006886ed1b1f3828853b75c30d578aceb269ebe351ddecc6f4073fe680bb8f1509c9bfba6700cfdfff5107e492d |
Critical Severity - Know Your Exposure
A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.
Create a free account →