CVE-2023-2024: Improper Authentication for OpenBlue Enterprise Manager Data Collector
Published May 18, 2023
·Updated
Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unauthorized user under certain circumstances.
Affected Software
2 affected components
Johnsoncontrols Openblue Enterprise Manager Data Collector<3.2.5.75
Johnson Controls Inc. OpenBlue Enterprise Manager Data Collector: Firmware versions prior to 3.2.5.75
Remediation
Information
Update all OpenBlue Enterprise Manager Data Collector firmware to version 3.2.5.75.
Information
Contact your Customer Success Manager to obtain the update.
Event History
May 18, 2023
CVE Published
via MITRE·08:45 PM
Data Sourced
via MITRE·08:45 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2023-2024?
CVE-2023-2024 is a vulnerability that allows unauthorized access to OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75.
2
What is the severity of CVE-2023-2024?
CVE-2023-2024 has a severity rating of critical with a CVSS score of 7.5.
3
How does CVE-2023-2024 affect OpenBlue Enterprise Manager Data Collector?
CVE-2023-2024 allows access to an unauthorized user in certain circumstances.
4
How can I fix CVE-2023-2024?
To mitigate CVE-2023-2024, update OpenBlue Enterprise Manager Data Collector to version 3.2.5.75 or later.
5
Where can I find more information about CVE-2023-2024?
You can find more information about CVE-2023-2024 on the CISA website and the Johnson Controls security advisories.