#VU29167 Improper Verification of Cryptographic Signature in exacqVision Enterprise System Manager and exacqVision Web Service


Published: 2020-07-15

Vulnerability identifier: #VU29167

Vulnerability risk: Low

CVSSv3.1: 6.1 [CVSS:3.1/AV:N/AC:H/PR:H/UI:R/S:C/C:L/I:H/A:L/E:P/RL:O/RC:C]

CVE-ID: CVE-2020-9047

CWE-ID: CWE-347

Exploitation vector: Network

Exploit availability: Yes

Vulnerable software:
exacqVision Enterprise System Manager
Server applications / SCADA systems
exacqVision Web Service
Web applications / Other software

Vendor: Johnson Controls

Description

The vulnerability allows a remote user to compromise the target system.

The vulnerability exists due to the affected software does not verify the cryptographic signature for data. A remote administrator can download and run a malicious executable.

Mitigation
Install updates from vendor's website.

Vulnerable software versions

exacqVision Enterprise System Manager: 20.03.3.0

exacqVision Web Service: 20.03.2.0


External links
http://ics-cert.us-cert.gov/advisories/icsa-20-170-01
http://www.johnsoncontrols.com/-/media/jci/cyber-solutions/product-security-advisories/2020/jci-psa-2020-7-v1-exacqvision-web-service-and-enterprise-manager.pdf?la=en&hash=704888A69F52AD699D6FA19A96C3B1B3104D3741


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote authenticated privileged user via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.


Latest bulletins with this vulnerability