PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-32754 Johnson Controls, Inc. CVE debrief

Johnson Controls Kantech door controllers (KT1, KT2, and KT400 Rev01) broadcast sensitive device information when operating in factory reset mode awaiting initial configuration. Specifically, the controllers transmit their MAC address, serial number, and firmware version. This information exposure ceases once the device completes configuration. The vulnerability requires adjacent network access and high attack complexity, with no privileges or user interaction needed. The CVSS 3.1 score of 3.1 reflects limited confidentiality impact with no integrity or availability effects.

Vendor
Johnson Controls, Inc.
Product
Kantech KT1 Door Controller, Rev01
CVSS
LOW 3.1
CISA KEV
Not listed in stored evidence
Original CVE published
2024-07-02
Original CVE updated
2024-07-02
Advisory published
2024-07-02
Advisory updated
2024-07-02

Who should care

Organizations deploying Johnson Controls Kantech door controllers, particularly security teams managing physical access control infrastructure, facility managers responsible for building security systems, and OT/ICS security practitioners concerned with information exposure during device provisioning.

Technical summary

The vulnerability exists in the factory reset state of Kantech KT1, KT2, and KT400 door controllers. When awaiting initial setup, these devices broadcast identifying information including MAC address, serial number, and firmware version. This broadcast behavior terminates upon successful configuration. The attack vector is adjacent (AV:A) with high complexity (AC:H), requiring no privileges or user interaction. The confidentiality impact is low (C:L) with no integrity or availability impact. Affected versions are KT1/KT2 Rev01 firmware ≤2.09.01 and KT400 Rev01 firmware ≤3.01.16. Remediation requires firmware updates to specified minimum versions.

Defensive priority

low

Recommended defensive actions

  • Update Kantech KT1 and KT2 Door Controllers to firmware version 3.10.12 or later
  • Update Kantech KT400 Door Controller to firmware version 3.03 or later
  • Complete initial device configuration promptly to exit factory reset mode
  • Restrict physical and network access to devices during initial setup
  • Consult Johnson Controls Product Security Advisory JCI-PSA-2024-13 v1 for detailed mitigation instructions

Evidence notes

CISA published advisory ICSA-24-184-01 on 2024-07-02. The source CSAF document identifies three affected product variants with specific firmware version thresholds. Johnson Controls has issued Product Security Advisory JCI-PSA-2024-13 v1 with detailed remediation guidance.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-32754 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-32754

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-32754 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-32754

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-184-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-184-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.