Johnson Controls C-CURE 9000 and Victor application server
Johnson Controls C-CURE 9000 and Victor application server have security vulnerabilities. An attacker can use these vulnerabilities to execute code remotely. This can happen if the attacker has network access.
Reported by 1 outlet — CISA. See all sources ↓
Johnson Controls C-CURE 9000 and Victor application server have security problems. These problems can let an attacker control the server from a distance. This can happen if the attacker is connected to the same network.
Why it matters
This is important because it can affect many companies and organizations that use these servers. It can also let attackers do bad things, like steal information.
- What are the security vulnerabilities?
- The vulnerabilities are Server-Side Request Forgery (SSRF) and Execution with Unnecessary Privileges.
- What can happen if an attacker uses these vulnerabilities?
- An attacker can execute code remotely and control the server.
- Which versions of the server are affected?
- The affected versions are C-CURE 9000 and victor <=v2.90_v3.0 victor Web <=v7.1.
How outlets are framing the same story
These are the main editorial angles found across reporting. Use them to quickly compare what different outlets emphasize, omit, or question.
All outlets report the same facts about the security vulnerabilities in Johnson Controls C-CURE 9000 and Victor application server. They all explain that an attacker can use these vulnerabilities to execute code remotely.
- Coverage cardFraming signal1AngleScouting report
Security vulnerabilities in Johnson Controls C-CURE 9000 and Victor application server
Sources1TypeAngleCISAReports on the specific vulnerabilities and affected versions.