CVE-2024-0912: CCURE passwords exposed to administrators

Published Jun 5, 2024
·
Updated

Under certain circumstances the Microsoft® Internet Information Server (IIS) used to host the C•CURE 9000 Web Server will log Microsoft Windows credential details within logs. There is no impact to non-web service interfaces C•CURE 9000 or prior versions

Affected Software

1 affected component
Johnsoncontrols Software House C-cure 9000 Siteserver=3.00.2

Remediation

Information

Update C•CURE 9000 to version 3.00.2 CU02 or 3.00.3 Change the password for the impacted windows accounts. Delete the api.log log file (or remove instances of passwords from the log file with a text editor) located at "C:\Program Files (x86)\Tyco\victorWebServices\victorWebsite\Logs\archives"

Event History

Jun 5, 2024
CVE Published
via MITRE·11:23 PM
Data Sourced
via MITRE·11:23 PM
RemedyDescriptionWeakness
Jun 6, 2024
Data Sourced
via NVD·12:15 AM
DescriptionWeakness

Frequently Asked Questions

1

What is the severity of CVE-2024-0912?

CVE-2024-0912 is considered a medium severity vulnerability due to the potential exposure of sensitive credential information.

2

How do I fix CVE-2024-0912?

To mitigate CVE-2024-0912, apply the recommended patches from Johnson Controls for the C•CURE 9000 Web Server version 3.00.2.

3

What types of credentials are exposed in CVE-2024-0912?

CVE-2024-0912 can log Microsoft Windows credential details in the IIS logs under certain circumstances.

4

Which versions of C•CURE 9000 are affected by CVE-2024-0912?

CVE-2024-0912 specifically affects C•CURE 9000 Siteserver version 3.00.2.

5

Does CVE-2024-0912 impact other versions of C•CURE 9000?

No, CVE-2024-0912 only impacts the C•CURE 9000 Web Server version 3.00.2 and not prior versions or non-web service interfaces.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203