ICSA-20-324-01: Victor web client vulnerability
Affected Software
2 affected components
Sensormatic Electronics, LLC; a subsidiary of Johnson Controls All versions of victor Web Client up to and including v5.6
Sensormatic Electronics, LLC; a subsidiary of Johnson Controls All versions of C•CURE Web Client up to and including v2.90
Event History
Feb 24, 2025
Advisory Published
01:33 AM
Frequently Asked Questions
1
What is the severity of ICSA-20-324-01?
The severity of ICSA-20-324-01 is high due to the potential for unauthenticated remote code execution.
2
How do I fix ICSA-20-324-01?
To fix ICSA-20-324-01, upgrade to the latest version of the Sensormatic victor Web Client and C•CURE Web Client software.
3
What vulnerabilities are addressed in ICSA-20-324-01?
ICSA-20-324-01 addresses vulnerabilities in all versions of the Victor Web Client up to and including v5.6 and C•CURE Web Client up to and including v2.90.
4
Are there any workarounds for ICSA-20-324-01?
Temporary workarounds for ICSA-20-324-01 include restricting network access to affected systems.
5
What systems are affected by ICSA-20-324-01?
ICSA-20-324-01 affects all versions of the victor Web Client and C•CURE Web Client from Sensormatic Electronics, LLC.