PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-32862 Johnson Controls Inc. CVE debrief

CVE-2024-32862 is a medium-severity vulnerability in Johnson Controls exacqVision Web Service version 22.12.1.0, published by CISA on August 1, 2024. The vulnerability stems from insufficient protection against untrusted domains under certain circumstances, which could allow cross-origin or cross-domain attacks against the web service. The CVSS 3.1 score of 6.8 reflects network attack vector, high attack complexity, no required privileges, but user interaction required, with high impact to confidentiality and integrity but no availability impact. Johnson Controls has released version 24.06 as a vendor fix and published detailed mitigation guidance in Product Security Advisory JCI-PSA-2024-15.

Vendor
Johnson Controls Inc.
Product
exacqVision Web Service
CVSS
MEDIUM 6.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-08-01
Original CVE updated
2024-08-01
Advisory published
2024-08-01
Advisory updated
2024-08-01

Who should care

Organizations operating Johnson Controls exacqVision video management systems, particularly security operations centers and physical security teams managing IP camera deployments. Critical infrastructure operators in sectors using exacqVision for surveillance and access control should prioritize patching due to potential integrity and confidentiality impacts on security footage and system configuration.

Technical summary

The exacqVision Web Service 22.12.1.0 fails to adequately restrict or validate interactions from untrusted domains, creating conditions for cross-origin attacks. The attack requires network access and user interaction, with high complexity reducing but not eliminating exploitation risk. Successful exploitation could compromise confidentiality and integrity of the web service. The fix in version 24.06 addresses the insufficient domain protection.

Defensive priority

medium

Recommended defensive actions

  • Update exacqVision Web Service to version 24.06 or later per vendor guidance
  • Review Johnson Controls Product Security Advisory JCI-PSA-2024-15 for detailed mitigation instructions
  • Implement network segmentation to limit exposure of exacqVision Web Service to untrusted domains
  • Apply CISA ICS recommended practices for defense-in-depth security controls
  • Monitor for anomalous cross-origin requests to exacqVision Web Service endpoints

Evidence notes

Vulnerability description and remediation details sourced from CISA CSAF advisory ICSA-24-214-02. Affected product version 22.12.1.0 confirmed through CSAF product tree. Vendor fix version 24.06 and mitigation reference JCI-PSA-2024-15 documented in CSAF remediations section. CVSS 3.1 vector AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:N provided in source references.

Official resources

2024-08-01