PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-32931 Johnson Controls CVE debrief

CVE-2024-32931 is a medium-severity information disclosure vulnerability in Johnson Controls exacqVision Web Service versions 24.03 and prior. Under certain conditions, the web service can expose authentication token details within communications, potentially allowing an attacker with network access and low privileges to obtain sensitive authentication material. The vulnerability was published by CISA on August 1, 2024, as ICSA-24-214-06. Johnson Controls has released version 24.06 to address this issue. Organizations should prioritize updating affected installations and review the vendor's Product Security Advisory JCI-PSA-2024-19 for additional mitigation guidance.

Vendor
Johnson Controls
Product
exacqVision Web Service
CVSS
MEDIUM 5.7
CISA KEV
Not listed in stored evidence
Original CVE published
2024-08-01
Original CVE updated
2024-08-01
Advisory published
2024-08-01
Advisory updated
2024-08-01

Who should care

Organizations operating Johnson Controls exacqVision video management systems, particularly security operations centers, physical security teams, and critical infrastructure operators using exacqVision Web Service for video surveillance management. System integrators and managed security service providers supporting exacqVision deployments should also prioritize this update.

Technical summary

The exacqVision Web Service, a video management system component, fails to adequately protect authentication token details in communications under specific circumstances. Affected versions (24.03 and prior) may transmit or expose token information that could be intercepted by an attacker with network access. The CVSS 3.1 score of 5.7 reflects network accessibility, low attack complexity, and required low privileges with user interaction, yielding high confidentiality impact but no integrity or availability impact. The vulnerability is classified as CWE-200 (Information Exposure). Remediation requires updating to version 24.06.

Defensive priority

medium

Recommended defensive actions

  • Update exacqVision Web Service to version 24.06 or later
  • Review Johnson Controls Product Security Advisory JCI-PSA-2024-19 for detailed mitigation instructions
  • Monitor network traffic for unusual authentication patterns that may indicate token exposure
  • Apply network segmentation to limit exposure of exacqVision Web Service instances
  • Follow CISA ICS recommended practices for securing industrial control systems

Evidence notes

CISA published advisory ICSA-24-214-06 on 2024-08-01 identifying authentication token exposure in exacqVision Web Service ≤24.03. CVSS 3.1 vector AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N indicates network attack vector with low attack complexity, requiring low privileges and user interaction, resulting in high confidentiality impact. Vendor fix available in version 24.06.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-32931 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-32931

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-32931 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-32931

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Johnson Controls exacqVision Web Service

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-214-06.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-214-06

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.