PatchSiren cyber security CVE debrief
CVE-2024-32931 Johnson Controls CVE debrief
CVE-2024-32931 is a medium-severity information disclosure vulnerability in Johnson Controls exacqVision Web Service versions 24.03 and prior. Under certain conditions, the web service can expose authentication token details within communications, potentially allowing an attacker with network access and low privileges to obtain sensitive authentication material. The vulnerability was published by CISA on August 1, 2024, as ICSA-24-214-06. Johnson Controls has released version 24.06 to address this issue. Organizations should prioritize updating affected installations and review the vendor's Product Security Advisory JCI-PSA-2024-19 for additional mitigation guidance.
- Vendor
- Johnson Controls
- Product
- exacqVision Web Service
- CVSS
- MEDIUM 5.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-08-01
- Original CVE updated
- 2024-08-01
- Advisory published
- 2024-08-01
- Advisory updated
- 2024-08-01
Who should care
Organizations operating Johnson Controls exacqVision video management systems, particularly security operations centers, physical security teams, and critical infrastructure operators using exacqVision Web Service for video surveillance management. System integrators and managed security service providers supporting exacqVision deployments should also prioritize this update.
Technical summary
The exacqVision Web Service, a video management system component, fails to adequately protect authentication token details in communications under specific circumstances. Affected versions (24.03 and prior) may transmit or expose token information that could be intercepted by an attacker with network access. The CVSS 3.1 score of 5.7 reflects network accessibility, low attack complexity, and required low privileges with user interaction, yielding high confidentiality impact but no integrity or availability impact. The vulnerability is classified as CWE-200 (Information Exposure). Remediation requires updating to version 24.06.
Defensive priority
medium
Recommended defensive actions
- Update exacqVision Web Service to version 24.06 or later
- Review Johnson Controls Product Security Advisory JCI-PSA-2024-19 for detailed mitigation instructions
- Monitor network traffic for unusual authentication patterns that may indicate token exposure
- Apply network segmentation to limit exposure of exacqVision Web Service instances
- Follow CISA ICS recommended practices for securing industrial control systems
Evidence notes
CISA published advisory ICSA-24-214-06 on 2024-08-01 identifying authentication token exposure in exacqVision Web Service ≤24.03. CVSS 3.1 vector AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:N indicates network attack vector with low attack complexity, requiring low privileges and user interaction, resulting in high confidentiality impact. Vendor fix available in version 24.06.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-32931 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-32931
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-32931 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-32931
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Johnson Controls exacqVision Web Service
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-214-06.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-214-06
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.