ALC WebCTRL Carrier i-Vu Access Control Bypass
Vulnerability Description
The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in versions up to and including 8.5 allows a malicious actor to bypass intended access restrictions and expose sensitive information via the web based building automation server.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-5539
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Steve Knabe from Praetorian
More from Automated Logic
View All →Affected Vendor
Automated Logic
View all reports →