PatchSiren cyber security CVE debrief
CVE-2024-32862 Johnson Controls Inc. CVE debrief
CVE-2024-32862 is a medium-severity vulnerability in Johnson Controls exacqVision Web Service version 22.12.1.0, published by CISA on August 1, 2024. The vulnerability stems from insufficient protection against untrusted domains under certain circumstances, which could allow cross-origin or cross-domain attacks against the web service. The CVSS 3.1 score of 6.8 reflects network attack vector, high attack complexity, no required privileges, but user interaction required, with high impact to confidentiality and integrity but no availability impact. Johnson Controls has released version 24.06 as a vendor fix and published detailed mitigation guidance in Product Security Advisory JCI-PSA-2024-15.
- Vendor
- Johnson Controls Inc.
- Product
- exacqVision Web Service
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-08-01
- Original CVE updated
- 2024-08-01
- Advisory published
- 2024-08-01
- Advisory updated
- 2024-08-01
Who should care
Organizations operating Johnson Controls exacqVision video management systems, particularly security operations centers and physical security teams managing IP camera deployments. Critical infrastructure operators in sectors using exacqVision for surveillance and access control should prioritize patching due to potential integrity and confidentiality impacts on security footage and system configuration.
Technical summary
The exacqVision Web Service 22.12.1.0 fails to adequately restrict or validate interactions from untrusted domains, creating conditions for cross-origin attacks. The attack requires network access and user interaction, with high complexity reducing but not eliminating exploitation risk. Successful exploitation could compromise confidentiality and integrity of the web service. The fix in version 24.06 addresses the insufficient domain protection.
Defensive priority
medium
Recommended defensive actions
- Update exacqVision Web Service to version 24.06 or later per vendor guidance
- Review Johnson Controls Product Security Advisory JCI-PSA-2024-15 for detailed mitigation instructions
- Implement network segmentation to limit exposure of exacqVision Web Service to untrusted domains
- Apply CISA ICS recommended practices for defense-in-depth security controls
- Monitor for anomalous cross-origin requests to exacqVision Web Service endpoints
Evidence notes
Vulnerability description and remediation details sourced from CISA CSAF advisory ICSA-24-214-02. Affected product version 22.12.1.0 confirmed through CSAF product tree. Vendor fix version 24.06 and mitigation reference JCI-PSA-2024-15 documented in CSAF remediations section. CVSS 3.1 vector AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N provided in source references.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-32862 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-32862
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-32862 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-32862
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-214-02.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-214-02
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.