CVE-2024-32758

Under certain circumstances the communication between exacqVision Client and exacqVision Server will use insufficient key length and exchange
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:johnsoncontrols:exacqvision_server:*:*:*:*:*:*:*:*
cpe:2.3:a:johnsoncontrols:exacqvision_client:*:*:*:*:*:*:*:*

History

09 Aug 2024, 19:00

Type Values Removed Values Added
First Time Johnsoncontrols
Johnsoncontrols exacqvision Server
Johnsoncontrols exacqvision Client
CWE CWE-326
CPE cpe:2.3:a:johnsoncontrols:exacqvision_server:*:*:*:*:*:*:*:*
cpe:2.3:a:johnsoncontrols:exacqvision_client:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
References () https://www.cisa.gov/news-events/ics-advisories/icsa-24-214-01 - () https://www.cisa.gov/news-events/ics-advisories/icsa-24-214-01 - Third Party Advisory, US Government Resource
References () https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories - () https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories - Vendor Advisory

01 Aug 2024, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-01 22:15

Updated : 2024-08-09 19:00


NVD link : CVE-2024-32758

Mitre link : CVE-2024-32758


JSON object : View

Products Affected

johnsoncontrols

  • exacqvision_server
  • exacqvision_client
CWE
CWE-326

Inadequate Encryption Strength