Known vulnerabilities in Metasys Network Automation Engine (NAE55)
Vendor:
Johnson Controls
Software CPE:
cpe:2.3:h:johnson_controls:metasys_network_automation_engine_nae55:*:*:*:*:*:*:*:*
Website:
https://www.johnsoncontrols.com/
Total vulnerabilities:
2
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
Vulnerabilities (2)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU83988 - Resource exhaustion CVE-2023-4486 |
CWE-400 | Medium | 12.0.4 | 08.12.2023 |
SB2023120803 |
||
| #VU25987 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2020-9044 |
CWE-611 | High | - | 11.03.2020 |
SB2020031122 |