victor Web Client and C•CURE Web Client JSON Web Token (JWT) Vulnerability
Vulnerability Description
A vulnerability in specified versions of American Dynamics victor Web Client and Software House C•CURE Web Client could allow an unauthenticated attacker on the network to create and sign their own JSON Web Token and use it to execute an HTTP API Method without the need for valid authentication/authorization. Under certain circumstances, this could be used by an attacker to impact system availability by conducting a Denial of Service attack.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-9049
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Joachim Kerschbaumer reported this vulnerability to Johnson Controls, Inc.
References
More from Johnson Controls
View All →Affected Vendor
Johnson Controls
View all reports →