Sensormatic Electronics, LLC, a subsidiary of Johnson Controls Inc., has and update available to handle an observable response discrepancy in its C-CURE 9000, according to a report with CISA.

Successful exploitation of this vulnerability, discovered by Kim Syversen and Mathias Kjølleberg Førland who reported this vulnerability to Johnson Controls, could allow an unauthorized user to enumerate user accounts.

Johnson Controls Inc. reports this vulnerability affects the following Sensormatic Electronics C-CURE 9000 security management systems: C-CURE 9000 version 2.90 and prior.

In the vulnerability, Sensormatic Electronics C•CURE 9000, version 2.90 and prior, provides responses to incoming requests that could reveal internal state information to an unauthorized user.

CVE-2021-36201 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 4.3.

Schneider Bold

The product sees use mainly in the critical manufacturing sector, and on a global basis.

No known public exploits specifically target this vulnerability. This vulnerability is not exploitable remotely. This vulnerability has a low attack complexity.

Johnson Controls recommends users update or upgrade to one of the two versions below:

For more detailed mitigation instructions, click on Johnson Controls Product Security Advisory JCI-PSA-2022-12 v1.

ISSSource

Pin It on Pinterest

Share This