CVE-2020-9049 - CVE House
Back to Database
Status published High CVE-2020-9049

victor Web Client and C•CURE Web Client JSON Web Token (JWT) Vulnerability

Vulnerability Description

A vulnerability in specified versions of American Dynamics victor Web Client and Software House C•CURE Web Client could allow an unauthenticated attacker on the network to create and sign their own JSON Web Token and use it to execute an HTTP API Method without the need for valid authentication/authorization. Under certain circumstances, this could be used by an attacker to impact system availability by conducting a Denial of Service attack.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-9049

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • Joachim Kerschbaumer reported this vulnerability to Johnson Controls, Inc.

Affected Vendor

Johnson Controls

View all reports →

Affected Software

victor Web Client version 5.6 and prior, C•CURE Web Client version 2.90 and prior (Note - This does not affect the new web-based C•CURE 9000 client that was introduced in C•CURE 9000 v2.90)
Vulnerable Versions:
unspecified

Timeline

Official Publish: November 19th, 2020
Last Modified: September 17th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:L

Weaknesses (CWE)