CVE-2024-32752

The iSTAR door controllers running firmware prior to version 6.6.B, does not support authenticated communications with ICU, which may allow an attacker to gain unauthorized access
Configurations

No configuration.

History

24 Apr 2025, 20:15

Type Values Removed Values Added
References
  • () https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories -
Summary (en) Under certain circumstances communications between the ICU tool and an iSTAR Pro door controller is susceptible to Machine-in-the-Middle attacks which could impact door control and configuration. (en) The iSTAR door controllers running firmware prior to version 6.6.B, does not support authenticated communications with ICU, which may allow an attacker to gain unauthorized access

Information

Published : 2024-06-06 21:15

Updated : 2025-04-24 20:15


NVD link : CVE-2024-32752

Mitre link : CVE-2024-32752

CVE.ORG link : CVE-2024-32752


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function