CWE
489
Advisory Published
Updated

CVE-2023-0954: Debug feature in Sensormatic Electronics Illustra Dome and PTZ cameras

First published: Thu Jun 08 2023(Updated: )

A debug feature in Sensormatic Electronics Illustra Pro Gen 4 Dome and PTZ cameras allows a user to compromise credentials after a long period of sustained attack.

Credit: productsecurity@jci.com

Affected SoftwareAffected VersionHow to fix
Johnsoncontrols Illustra Pro Gen 4 Dome Firmware<=ss016.05.09.04.0006
Johnsoncontrols Illustra Pro Gen 4 Dome
Johnsoncontrols Illustra Pro Gen 4 Ptz Firmware<=ss010.05.09.04.0022
Johnsoncontrols Illustra Pro Gen 4 Ptz
Sensormatic Electronics, a subsidiary of Johnson Controls, Inc. ​Pro Gen 4 Dome: Up to and including Illustra.SS016.05.09.04.0006
Sensormatic Electronics, a subsidiary of Johnson Controls, Inc. ​Pro Gen 4 PTZ: Up to and including Illustra.SS010.05.09.04.0022

Remedy

Update Illustra Pro Gen 4 Dome to version 6.00.00

Remedy

Update Illustra Pro Gen 4 PTZ to version 6.00.00

Remedy

The camera can be upgraded via the web GUI using firmware provided by Illustra which can be found on www.illustracameras.com http://www.illustracameras.com . The firmware can also be upgraded using the Illustra Connect tool (Windows based) or Illustra Tools (mobile app) or victor/VideoEdge, which also provides bulk firmware upgrade capability. Please refer to the respective application documents for further information.

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Parent vulnerabilities

(Appears in the following advisories)

Frequently Asked Questions

  • What is CVE-2023-0954?

    CVE-2023-0954 is a vulnerability in Sensormatic Electronics Illustra Pro Gen 4 Dome and PTZ cameras that allows a user to compromise credentials after a long period of sustained attack.

  • What is the severity of CVE-2023-0954?

    CVE-2023-0954 has a severity rating of 9.8 (critical).

  • Which software versions are affected by CVE-2023-0954?

    The Sensormatic Electronics Illustra Pro Gen 4 Dome firmware up to and including ss016.05.09.04.0006 and the Illustra Pro Gen 4 PTZ firmware up to and including ss010.05.09.04.0022 are affected by CVE-2023-0954.

  • How can the vulnerability be exploited?

    The vulnerability can be exploited by performing a long period of sustained attack to compromise credentials on the affected cameras.

  • Where can I find more information about CVE-2023-0954?

    You can find more information about CVE-2023-0954 from the official advisories published by CISA and Johnson Controls.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203