You are here

Johnson Controls exacqVision Server (ICSA-19-199-01)

Johnson Controls exacqVision Server (ICSA-19-199-01)

Created: Tuesday, July 23, 2019 - 09:36
Categories:
Cybersecurity

The NCCIC has published an advisory on an unquoted search path or element vulnerability in Johnson Controls exacqVision Server. This vulnerability impacts exacqVision server versions 9.6 and 9.8. Successful exploitation of this vulnerability could allow an unauthenticated user to elevate their privileges. Johnson Controls recommends users upgrade to the latest product, version 19.03. The NCCIC also advises of a series of measures for mitigating the vulnerability. Read the advisory at CISA.