Where
AND
-Infinity
0
Severity
7.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

A vulnerability in specified versions of American Dynamics victor Web Client and Software House C•CURE Web Client could allow an unauthenticated attacker on the network to create and sign their own JSON Web Token and use it to execute an HTTP API Method without the need for valid authentication/authorization. Under certain circumstances, this could be used by an attacker to impact system availability by conducting a Denial of Service attack.

Remedy

victor Web Client • victor Web Client v5.6 and earlier – upgrade to v5.6 SP1 (victor Unified Client v5.6 SP1) Registered users can obtain the software update by downloading the update found here: https://www.americandynamics.net/support/SoftwareDownloads.aspx. C•CURE Web Client C•CURE Web v2.60 and earlier - upgrade to a minimum of v2.70 and install the relevant update below. • C•CURE Web v2.70 - install the update WebClient_c2.70_5.2_Update02 • C•CURE Web v2.80 - install the update WebClient_c2.80_v5.4.1_Update04 • C•CURE Web v2.90 - install the update CCureWeb_2.90_Update01 Registered users can obtain the software update by downloading the update found here: https://swhouse.com/Support/SoftwareDownloads.aspx.
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203