First published: Thu Jul 01 2021(Updated: )
An insecure client auto update feature in C-CURE 9000 can allow remote execution of lower privileged Windows programs.
Credit: productsecurity@jci.com
Affected Software | Affected Version | How to fix |
---|---|---|
Johnsoncontrols C-cure 9000 Firmware | <2.80 | |
Johnsoncontrols C-cure 9000 | ||
Sensormatic Electronics, LLC, a subsidiary of Johnson Controls C-CURE 9000 | <2.80 | 2.80 |
Upgrade to C-CURE 9000 version 2.80 or above. If this is not possible then follow published instructions for disabling the auto update feature located here https://support.swhouse.com/ and search for the document SWH-TAB-nID-000006545.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27660 refers to an insecure client auto-update feature in C-CURE 9000 that can allow remote execution of lower privileged Windows programs.
CVE-2021-27660 has a severity rating of 8.8 (high).
C-CURE 9000 firmware versions up to and including 2.80 are affected by CVE-2021-27660.
CVE-2021-27660 can be exploited through the insecure client auto-update feature in C-CURE 9000, allowing remote execution of lower privileged Windows programs.
Johnson Controls has released firmware version 2.81 that addresses the insecure client auto-update feature vulnerability in C-CURE 9000.