PatchSiren cyber security CVE debrief
CVE-2024-32862 Johnson Controls Inc. CVE debrief
CVE-2024-32862 is a medium-severity vulnerability in Johnson Controls exacqVision Web Service version 22.12.1.0, published by CISA on August 1, 2024. The vulnerability stems from insufficient protection against untrusted domains under certain circumstances, which could allow cross-origin or cross-domain attacks against the web service. The CVSS 3.1 score of 6.8 reflects network attack vector, high attack complexity, no required privileges, but user interaction required, with high impact to confidentiality and integrity but no availability impact. Johnson Controls has released version 24.06 as a vendor fix and published detailed mitigation guidance in Product Security Advisory JCI-PSA-2024-15.
- Vendor
- Johnson Controls Inc.
- Product
- exacqVision Web Service
- CVSS
- MEDIUM 6.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-08-01
- Original CVE updated
- 2024-08-01
- Advisory published
- 2024-08-01
- Advisory updated
- 2024-08-01
Who should care
Organizations operating Johnson Controls exacqVision video management systems, particularly security operations centers and physical security teams managing IP camera deployments. Critical infrastructure operators in sectors using exacqVision for surveillance and access control should prioritize patching due to potential integrity and confidentiality impacts on security footage and system configuration.
Technical summary
The exacqVision Web Service 22.12.1.0 fails to adequately restrict or validate interactions from untrusted domains, creating conditions for cross-origin attacks. The attack requires network access and user interaction, with high complexity reducing but not eliminating exploitation risk. Successful exploitation could compromise confidentiality and integrity of the web service. The fix in version 24.06 addresses the insufficient domain protection.
Defensive priority
medium
Recommended defensive actions
- Update exacqVision Web Service to version 24.06 or later per vendor guidance
- Review Johnson Controls Product Security Advisory JCI-PSA-2024-15 for detailed mitigation instructions
- Implement network segmentation to limit exposure of exacqVision Web Service to untrusted domains
- Apply CISA ICS recommended practices for defense-in-depth security controls
- Monitor for anomalous cross-origin requests to exacqVision Web Service endpoints
Evidence notes
Vulnerability description and remediation details sourced from CISA CSAF advisory ICSA-24-214-02. Affected product version 22.12.1.0 confirmed through CSAF product tree. Vendor fix version 24.06 and mitigation reference JCI-PSA-2024-15 documented in CSAF remediations section. CVSS 3.1 vector AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N provided in source references.
Official resources
-
CVE-2024-32862 CVE record
CVE.org
-
CVE-2024-32862 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
2024-08-01