Under certain circumstances the Microsoft® Internet Information Server (IIS) used to host the C•CURE 9000 Web Server will log Microsoft Windows credential details within logs. There is no impact to non-web service interfaces C•CURE 9000 or prior versions
References
Link | Resource |
---|---|
https://www.cisa.gov/news-events/ics-advisories/icsa-24-135-03 | Third Party Advisory US Government Resource |
https://www.johnsoncontrols.com/-/media/jci/cyber-solutions/product-security-advisories/2024/jci-psa-2024-04.pdf | Product |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2024-06-06 00:15
Updated : 2024-07-18 18:56
NVD link : CVE-2024-0912
Mitre link : CVE-2024-0912
CVE.ORG link : CVE-2024-0912
JSON object : View
Products Affected
johnsoncontrols
- software_house_c-cure_9000_siteserver
CWE
CWE-532
Insertion of Sensitive Information into Log File