CVE-2021-27660: C-CURE 9000
Published Jul 1, 2021
·Updated
An insecure client auto update feature in C-CURE 9000 can allow remote execution of lower privileged Windows programs.
Affected Software
3 affected componentsFixes available
Sensormatic Electronics, LLC, a subsidiary of Johnson Controls C-CURE 9000<2.80
2.80
Johnsoncontrols C-cure 9000 Firmware<2.80
Johnsoncontrols C-cure 9000
Remediation
Information
Upgrade to C-CURE 9000 version 2.80 or above. If this is not possible then follow published instructions for disabling the auto update feature located here https://support.swhouse.com/ and search for the document SWH-TAB-nID-000006545.
Event History
Jul 1, 2021
CVE Published
via MITRE·01:36 PM
Data Sourced
via MITRE·01:36 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2021-27660?
CVE-2021-27660 refers to an insecure client auto-update feature in C-CURE 9000 that can allow remote execution of lower privileged Windows programs.
2
What is the severity of CVE-2021-27660?
CVE-2021-27660 has a severity rating of 8.8 (high).
3
Which software is affected by CVE-2021-27660?
C-CURE 9000 firmware versions up to and including 2.80 are affected by CVE-2021-27660.
4
How can CVE-2021-27660 be exploited?
CVE-2021-27660 can be exploited through the insecure client auto-update feature in C-CURE 9000, allowing remote execution of lower privileged Windows programs.
5
Is there a fix for CVE-2021-27660?
Johnson Controls has released firmware version 2.81 that addresses the insecure client auto-update feature vulnerability in C-CURE 9000.