ExacqVision Web Service Vulnerability: How to Prevent a CSRF Disaster

Stay alert! Johnson Controls’ exacqVision Web Service, versions 24.03 and prior, are vulnerable to Cross-Site Request Forgery (CSRF). Exploitable remotely, this flaw could let attackers perform admin-level operations. Update to version 24.06 to mitigate the risk.

Hot Take:

Looks like Johnson Controls’ exacqVision Web Service got caught in a cross-site request forgery act. Who knew that even surveillance systems needed better security surveillance?

Key Points:

  • CVSS v3 score: 6.8 — not great, not terrible.
  • Exploitable remotely — hackers don’t even need to leave their couch.
  • Vendor: Johnson Controls, Inc. — oops, they did it again.
  • Vulnerability: Cross-Site Request Forgery (CSRF) — sounds fancy, isn’t it?
  • Mitigation: Update to version 24.06 — patch it up, people!

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here