news.mlab.sh
Back to the feed
vulnerability

Johnson Controls C-CURE 9000 and Victor application server

High
Summary

Johnson Controls has issued security advisories regarding critical vulnerabilities in its C-CURE 9000 and Victor application servers, as well as the victor Web application. Exploitation could allow an unauthenticated attacker on a neighboring network to execute arbitrary code, potentially impacting physical security controls and leading to low-privilege users accessing sensitive information. Updates to versions 3.20 or later of C-CURE 9000/Victor and version 7.0 or later of victor Web are recommended to address these issues.

Johnson Controls has issued security advisories highlighting critical vulnerabilities within its C-CURE 9000 and Victor application servers, alongside the victor Web application. These vulnerabilities could be exploited to allow an unauthenticated attacker on a neighboring network to execute arbitrary code, significantly impacting physical security controls. Specifically, successful exploitation could enable an attacker to forge server-side HTTP requests from the victor Web application, potentially interacting with internal services and leading to unauthorized information disclosure or lateral movement within the network. Furthermore, low-privilege users could gain access to sensitive pages and audit logs, enabling further attacks or unauthorized administrative actions.

The affected products include Johnson Controls C-CURE 9000 and Victor application server (<=v2.90_v3.0 and victor Web <=v7.1). The vendor recommends upgrading to C-CURE 9000/Victor version 3.20 or later, and victor Web version 7.0 or later, which contain fixes for these vulnerabilities. Independent retesting has validated these fixes.

To mitigate these risks, Johnson Controls advises implementing network segmentation, isolating the application servers on a dedicated network segment and restricting access to port 8999 to authorized systems. Additional defenses include firewall/access control lists to block unnecessary inbound connections, intrusion detection/prevention systems tuned to detect known .NET deserialization exploit payloads (e.g., ysoserial.net patterns), application whitelisting to prevent unauthorized executables, and least privilege enforcement for the application server process. Monitoring and auditing are also recommended, specifically for anomalous process creation by SoftwareHouse.CrossFire.Server.exe. Finally, disabling unnecessary services, such as the ClientConnectionManager_NF.SynchronousServerNotification callback interface, if not required, is advised to reduce the attack surface.

For more detailed mitigation instructions and vendor advisories, please refer to: https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories.

Relevant CWEs: CWE-918 Server-Side Request Forgery (SSRF), CWE-250 Execution with Unnecessary Privileges.

Read the full article at CISA Advisories