CVE-2024-32752

The iSTAR door controllers running firmware prior to version 6.6.B, does not support authenticated communications with ICU, which may allow an attacker to gain unauthorized access
Configurations

No configuration.

History

24 Apr 2025, 20:15

Type Values Removed Values Added
References
  • () https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories -
Summary (en) Under certain circumstances communications between the ICU tool and an iSTAR Pro door controller is susceptible to Machine-in-the-Middle attacks which could impact door control and configuration. (en) The iSTAR door controllers running firmware prior to version 6.6.B, does not support authenticated communications with ICU, which may allow an attacker to gain unauthorized access

21 Nov 2024, 09:15

Type Values Removed Values Added
References () https://www.cisa.gov/news-events/ics-advisories/icsa-24-158-04 - () https://www.cisa.gov/news-events/ics-advisories/icsa-24-158-04 -
References () https://www.johnsoncontrols.com/-/media/jci/cyber-solutions/product-security-advisories/2024/jci-psa-2024-06.pdf - () https://www.johnsoncontrols.com/-/media/jci/cyber-solutions/product-security-advisories/2024/jci-psa-2024-06.pdf -

03 Jul 2024, 01:57

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.1

07 Jun 2024, 14:56

Type Values Removed Values Added
Summary
  • (es) En determinadas circunstancias, las comunicaciones entre la herramienta ICU y un controlador de puerta iSTAR Pro son susceptibles a ataques Machine-in-the-Middle que podrían afectar el control y la configuración de la puerta.

06 Jun 2024, 21:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-06-06 21:15

Updated : 2025-04-24 20:15


NVD link : CVE-2024-32752

Mitre link : CVE-2024-32752

CVE.ORG link : CVE-2024-32752


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function