Vulnerabilities > Johnsoncontrols > Exacqvision WEB Service > High

DATE CVE VULNERABILITY TITLE RISK
2024-08-01 CVE-2024-32862 Incorrect Comparison vulnerability in Johnsoncontrols Exacqvision web Service 20.06.11.0/20.06.3.0/21.03
Under certain circumstances the ExacqVision Web Services does not provide sufficient protection from untrusted domains.
network
low complexity
johnsoncontrols CWE-697
8.1
2024-08-01 CVE-2024-32863 Cross-Site Request Forgery (CSRF) vulnerability in Johnsoncontrols Exacqvision web Service 20.06.11.0/20.06.3.0/21.03
Under certain circumstances the exacqVision Web Services may be susceptible to Cross-Site Request Forgery (CSRF)
network
low complexity
johnsoncontrols CWE-352
8.8
2024-08-01 CVE-2024-32864 Cleartext Transmission of Sensitive Information vulnerability in Johnsoncontrols Exacqvision web Service 20.06.11.0/20.06.3.0/21.03
Under certain circumstances exacqVision Web Services will not enforce secure web communications (HTTPS)
network
low complexity
johnsoncontrols CWE-319
8.1
2021-03-18 CVE-2021-27656 Missing Authorization vulnerability in Johnsoncontrols Exacqvision web Service 20.06.11.0/20.06.3.0
A vulnerability in exacqVision Web Service 20.12.2.0 and prior could allow an unauthenticated attacker to view system-level information about the exacqVision Web Service and the operating system.
network
low complexity
johnsoncontrols CWE-862
7.5
2020-06-26 CVE-2020-9047 Improper Verification of Cryptographic Signature vulnerability in Johnsoncontrols products
A vulnerability exists that could allow the execution of unauthorized code or operating system commands on systems running exacqVision Web Service versions 20.06.3.0 and prior and exacqVision Enterprise Manager versions 20.06.4.0 and prior.
network
low complexity
johnsoncontrols CWE-347
7.2