First published: Tue Oct 11 2022(Updated: )
Under certain circumstances a CCURE Portal user could enumerate user accounts in CCURE 9000 version 2.90 and prior versions.
Credit: productsecurity@jci.com
Affected Software | Affected Version | How to fix |
---|---|---|
Johnsoncontrols C-cure 9000 Firmware | <=2.90 | |
Johnsoncontrols C-cure 9000 | ||
Sensormatic Electronics, LLC, a subsidiary of Johnson Controls Inc. C-CURE 9000 version 2.90 and prior |
Update C•CURE 9000 2.90 with patch 2.90 SP5 or upgrade C•CURE 9000 to version 3.0. The software can be downloaded here: https://www.swhouse.com/Support/SoftwareDownloads.aspx
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-36201.
The severity of CVE-2021-36201 is medium with a severity value of 5.3.
CCURE 9000 version 2.90 and prior versions are affected by CVE-2021-36201.
Under certain circumstances, a CCURE Portal user can enumerate user accounts in CCURE 9000 version 2.90 and prior versions.
You can find more information about CVE-2021-36201 at the following references: [CISA Advisory](https://www.cisa.gov/uscert/ics/advisories/icsa-22-284-03) and [Johnson Controls Security Advisories](https://www.johnsoncontrols.com/cyber-solutions/security-advisories).