First published: Thu Jun 08 2023(Updated: )
A debug feature in Sensormatic Electronics Illustra Pro Gen 4 Dome and PTZ cameras allows a user to compromise credentials after a long period of sustained attack.
Credit: productsecurity@jci.com
Affected Software | Affected Version | How to fix |
---|---|---|
Johnsoncontrols Illustra Pro Gen 4 Dome Firmware | <=ss016.05.09.04.0006 | |
Johnsoncontrols Illustra Pro Gen 4 Dome | ||
Johnsoncontrols Illustra Pro Gen 4 Ptz Firmware | <=ss010.05.09.04.0022 | |
Johnsoncontrols Illustra Pro Gen 4 Ptz | ||
Sensormatic Electronics, a subsidiary of Johnson Controls, Inc. Pro Gen 4 Dome: Up to and including Illustra.SS016.05.09.04.0006 | ||
Sensormatic Electronics, a subsidiary of Johnson Controls, Inc. Pro Gen 4 PTZ: Up to and including Illustra.SS010.05.09.04.0022 |
Update Illustra Pro Gen 4 Dome to version 6.00.00
Update Illustra Pro Gen 4 PTZ to version 6.00.00
The camera can be upgraded via the web GUI using firmware provided by Illustra which can be found on www.illustracameras.com http://www.illustracameras.com . The firmware can also be upgraded using the Illustra Connect tool (Windows based) or Illustra Tools (mobile app) or victor/VideoEdge, which also provides bulk firmware upgrade capability. Please refer to the respective application documents for further information.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-0954 is a vulnerability in Sensormatic Electronics Illustra Pro Gen 4 Dome and PTZ cameras that allows a user to compromise credentials after a long period of sustained attack.
CVE-2023-0954 has a severity rating of 9.8 (critical).
The Sensormatic Electronics Illustra Pro Gen 4 Dome firmware up to and including ss016.05.09.04.0006 and the Illustra Pro Gen 4 PTZ firmware up to and including ss010.05.09.04.0022 are affected by CVE-2023-0954.
The vulnerability can be exploited by performing a long period of sustained attack to compromise credentials on the affected cameras.
You can find more information about CVE-2023-0954 from the official advisories published by CISA and Johnson Controls.