CVE-2024-32864: exacqVison - HTTPS Session Establishment
Published Aug 1, 2024
·Updated
Under certain circumstances exacqVision Web Services will not enforce secure web communications (HTTPS)
Affected Software
1 affected component
Johnsoncontrols Exacqvision Web Service<=24.03
Remediation
Information
Update exacqVision Web Service to version 24.06
Event History
Aug 1, 2024
CVE Published
via MITRE·09:08 PM
Data Sourced
via MITRE·09:08 PM
RemedyDescriptionSeverityWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-32864?
CVE-2024-32864 is classified with a severity that suggests there is a significant risk associated with insecure web communications.
2
How do I fix CVE-2024-32864?
To fix CVE-2024-32864, ensure that exacqVision Web Services is configured to enforce secure web communications (HTTPS) and update to the latest version if available.
3
Which versions of exacqVision Web Services are affected by CVE-2024-32864?
CVE-2024-32864 affects exacqVision Web Service versions up to and including 24.03.
4
What are the potential consequences of CVE-2024-32864?
The potential consequences of CVE-2024-32864 include unauthorized access and interception of sensitive data due to non-enforced HTTPS.
5
Is there a specific workaround for CVE-2024-32864?
A specific workaround for CVE-2024-32864 involves manually configuring the system to utilize HTTPS for all communications.