Johnson Controls C-CURE 9000 and Victor application server

Summary

Johnson Controls C-CURE 9000 and Victor application server versions prior to v2.90_v3.0 and v7.1 respectively are affected by critical vulnerabilities. Successful exploitation could allow an unauthenticated adjacent network attacker to achieve remote code execution and impact physical security controls.

IFF Assessment

FOE

This article details critical vulnerabilities that could allow attackers to execute code remotely and compromise physical security systems, posing a significant threat to defenders.

Severity

9.6 Critical

The CVSS score of 9.6 indicates a critical severity, reflecting the potential for an unauthenticated adjacent network attacker to achieve arbitrary code execution, which could have a severe impact on confidentiality, integrity, and availability.

Defender Context

Defenders should prioritize patching or applying mitigations for Johnson Controls C-CURE 9000 and Victor application servers, as these vulnerabilities are critical and can lead to remote code execution. Network segmentation and access control are recommended defensive measures to limit the attack surface.

Read Full Story →