9
CVE-2024-32758
- EPSS 0.44%
- Veröffentlicht 01.08.2024 22:15:24
- Zuletzt bearbeitet 09.08.2024 19:00:17
- Quelle productsecurity@jci.com
- CVE-Watchlists
- Unerledigt
exacqVision - Key exchanges
Under certain circumstances the communication between exacqVision Client and exacqVision Server will use insufficient key length and exchange
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Johnsoncontrols ≫ Exacqvision Client Version < 24.06
Johnsoncontrols ≫ Exacqvision Server Version < 24.06
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.44% | 0.348 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
| productsecurity@jci.com | 9 | 0 | 0 |
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-326 Inadequate Encryption Strength
The product stores or transmits sensitive data using an encryption scheme that is theoretically sound, but is not strong enough for the level of protection required.
https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories
https://www.cisa.gov/news-events/ics-advisories/icsa-24-214-01