Categories
Knowledge Support Support Categories exacqVision Webservice Products Uncategorized

An Unauthenticated Remote User Could be Given Access to Credentials Stored in the Server

Overview:

Johnson Controls has confirmed a vulnerability impacting the exacqVision Web Service. The exacqVision Web Service is also included in the exacqVision Server Bundle along with the exacqVision Client and exacqVision Server. The exacqVision Web Service allows users to retrieve video and other data from exacqVision servers using a browser and mobile application. When passthrough / unauthenticated access is enabled, credentials for other systems connected to exacqVision could be exposed.

Impact:

Under certain configurations an unauthenticated remote user could be given access to credentials stored in the exacqVision Server.

Affected Versions:

  • exacqVision Web Service version 21.06.11.0 or older.

Mitigation:

Resources:

Categories
Knowledge Support Support exacqVision Server Categories Products

An Unauthenticated Remote User Could Exploit a Potential Integer Overflow Condition in the Server and Cause DoS

Overview:

Johnson Controls has confirmed a vulnerability impacting Exacq Technologies exacqVision. The exacqVision Server is also included in the exacqVision Server Bundle along with the exacqVision Client and exacqVision Web Service. Under certain circumstances an integer overflow condition could exist in the exacqVision Server.

Impact:

An unauthenticated remote user could exploit a potential integer overflow condition in the exacqVision Server with a specially crafted script and cause Denial of Service (DoS).

Affected Versions:

exacqVision Server 32‐bit version 21.06.11.0 or older.

Mitigation:

  • Upgrade exacqVision Server 32‐bit to version 21.09 or Upgrade to exacqVision Server 64‐bit.
  • Current users can obtain the critical software update from the Software Downloads location at: https://www.exacq.com/support/downloads.php

Resources: