CVE-2023-4486: Johnsoncontrols f4-Snc Firmware
High severity, CVSS 7.5. EPSS: 0.8% chance of exploitation in the next 30 days.
Under certain circumstances, invalid authentication credentials could be sent to the login endpoint of Johnson Controls Metasys NAE55, SNE, and SNC engines prior to versions 11.0.6 and 12.0.4 and Facility Explorer F4-SNC engines prior to versions 11.0.6 and 12.0.4 to cause denial-of-service.
Affected products
- Johnsoncontrols f4-Snc Firmware: before 11.0.6 (fixed in 11.0.6); from 12.0.0, before 12.0.4 (fixed in 12.0.4)
- Johnsoncontrols NAE55 Firmware: before 12.0.4 (fixed in 12.0.4)
- Johnsoncontrols SNC16120-04 Firmware: before 12.0.4 (fixed in 12.0.4)
- Johnsoncontrols SNC16120-0 Firmware: before 12.0.4 (fixed in 12.0.4)
- Johnsoncontrols SNC25150-04 Firmware: before 12.0.4 (fixed in 12.0.4)
- Johnsoncontrols SNC25150-0 Firmware: before 12.0.4 (fixed in 12.0.4)
- Johnsoncontrols SNE10500 Firmware: before 12.0.4 (fixed in 12.0.4)
- Johnsoncontrols SNE11000 Firmware: before 12.0.4 (fixed in 12.0.4)
- Johnsoncontrols SNE110L0 Firmware: before 12.0.4 (fixed in 12.0.4)
- Johnsoncontrols SNE22000 Firmware: before 12.0.4 (fixed in 12.0.4)
Published 2023-12-07. Last modified 2026-06-17.