CVE-2024-32863: exacqVison - CSRF issues with Web Service
Published Aug 1, 2024
·Updated
Under certain circumstances the exacqVision Web Services may be susceptible to Cross-Site Request Forgery (CSRF)
Affected Software
1 affected component
Johnsoncontrols Exacqvision Web Service<=24.03
Remediation
Information
Update exacqVision Web Service to version 24.06
Event History
Aug 1, 2024
CVE Published
via MITRE·08:59 PM
Data Sourced
via MITRE·08:59 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-32863?
The severity of CVE-2024-32863 is considered moderate due to its potential for Cross-Site Request Forgery (CSRF) attacks.
2
How do I fix CVE-2024-32863?
To fix CVE-2024-32863, ensure that you update the exacqVision Web Services to the latest version beyond 24.03.
3
What software versions are affected by CVE-2024-32863?
CVE-2024-32863 affects all versions of exacqVision Web Service up to and including version 24.03.
4
What are the potential impacts of CVE-2024-32863?
The potential impacts of CVE-2024-32863 include unauthorized actions being executed on behalf of users without their consent.
5
Is there a workaround for CVE-2024-32863?
Currently, no specific workarounds are recommended for mitigating CVE-2024-32863, so upgrading is advised.