CVE-2024-32752
Severity CVSS v4.0:
HIGH
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
06/06/2024
Last modified:
24/04/2025
Description
The iSTAR door controllers running firmware prior to version 6.6.B, does not support authenticated<br />
communications with ICU, which may allow an attacker to gain unauthorized access
Impact
Base Score 4.0
8.80
Severity 4.0
HIGH
Base Score 3.x
9.10
Severity 3.x
CRITICAL
References to Advisories, Solutions, and Tools
- https://www.cisa.gov/news-events/ics-advisories/icsa-24-158-04
- https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories
- https://www.cisa.gov/news-events/ics-advisories/icsa-24-158-04
- https://www.johnsoncontrols.com/-/media/jci/cyber-solutions/product-security-advisories/2024/jci-psa-2024-06.pdf



