CVE-2024-32752: Johnson Controls Software House iSTAR Configuration Utility (ICU) Tool
The iSTAR door controllers running firmware prior to version 6.6.B, does not support authenticated communications with ICU, which may allow an attacker to gain unauthorized access
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-32752?
CVE-2024-32752 is considered a high-severity vulnerability due to the potential for machine-in-the-middle attacks affecting door control and configuration.
How do I fix CVE-2024-32752?
To fix CVE-2024-32752, ensure that the ICU tool and iSTAR Pro door controller communications are secured and apply any patches or updates provided by Johnson Controls.
What systems are affected by CVE-2024-32752?
CVE-2024-32752 affects the Johnson Controls iSTAR Pro Door Controller under specific conditions.
What type of attack is CVE-2024-32752 susceptible to?
CVE-2024-32752 is susceptible to machine-in-the-middle attacks, which could compromise communication and control.
What impact could CVE-2024-32752 have on my system?
The impact of CVE-2024-32752 could include unauthorized access to door control and potential misconfiguration of security settings.