CVE-2024-0912: CCURE passwords exposed to administrators
Under certain circumstances the Microsoft® Internet Information Server (IIS) used to host the C•CURE 9000 Web Server will log Microsoft Windows credential details within logs. There is no impact to non-web service interfaces C•CURE 9000 or prior versions
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-0912?
CVE-2024-0912 is considered a medium severity vulnerability due to the potential exposure of sensitive credential information.
How do I fix CVE-2024-0912?
To mitigate CVE-2024-0912, apply the recommended patches from Johnson Controls for the C•CURE 9000 Web Server version 3.00.2.
What types of credentials are exposed in CVE-2024-0912?
CVE-2024-0912 can log Microsoft Windows credential details in the IIS logs under certain circumstances.
Which versions of C•CURE 9000 are affected by CVE-2024-0912?
CVE-2024-0912 specifically affects C•CURE 9000 Siteserver version 3.00.2.
Does CVE-2024-0912 impact other versions of C•CURE 9000?
No, CVE-2024-0912 only impacts the C•CURE 9000 Web Server version 3.00.2 and not prior versions or non-web service interfaces.