Software House iSTAR door controllers accepted unauthenticated ICU traffic
- Company
- Johnson Controls
- CVE ID
- CVE-2024-32752
- Severity
- Critical
- CVSS
- 9.10
- Source URL
- www.cisa.gov
- Vendor notified at
- 2024-06-06 00:00:00
iSTAR Pro, Edge, eX, Ultra and Ultra LT door controllers running firmware before 6.6.B did not authenticate communications with the iSTAR Configuration Utility, allowing tampering with controller configuration over the network.
Source: www.cisa.gov