QID 590554
Date Published: 2021-10-27
QID 590554: Johnson Controls exacqVision Denial of Service (DoS) Vulnerability (ICSA-21-280-03)
AFFECTED PRODUCTS
The following versions of Exacq Technologies exacqVision surveillance video software products are affected:
exacqVision Server 32-bit: Versions 21.06.11.0 and prior
QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys
Successful exploitation of this vulnerability could allow an unauthenticated remote user to exploit an integer overflow in the exacqVision Server with a specially crafted script and cause a denial-of-service condition.
Solution
Customers are advised to refer to CERT MITIGATIONS section ICSA-21-280-03 for affected packages and patching details.
Vendor References
- ICSA-21-280-03 -
www.us-cert.gov/ics/advisories/ICSA-21-280-03
CVEs related to QID 590554
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-21-280-03 |
|