Full Report
[Control Systems] Johnson Controls security advisory (AV26-1010)
Analysis Summary
# Vulnerability: Johnson Controls Illustra Standard- L4L China Improper Input Validation
## CVE Details
- **CVE ID:** CVE-2024-45377 (Associated with JCI-PSA-2024-37)
- **CVSS Score:** 9.8 (Critical)
- **CWE:** CWE-20 (Improper Input Validation) / CWE-287 (Improper Authentication)
## Affected Systems
- **Products:** Illustra Standard - L4L China (IP Cameras)
- **Versions:** All versions prior to v6.0.0.66394
- **Configurations:** Systems exposed to network traffic without adequate perimeter firewalling are at highest risk.
## Vulnerability Description
A critical vulnerability exists in the web server component of the Illustra Standard - L4L China cameras. The flaw stems from improper validation of input during the authentication process. An unauthenticated remote attacker can send a specially crafted network request to the device to bypass authentication, potentially gaining full administrative control over the camera's configuration and video streams.
## Exploitation
- **Status:** Not currently reported as exploited in the wild; No public PoC available as of this advisory date.
- **Complexity:** Low
- **Attack Vector:** Network
## Impact
- **Confidentiality:** High (Unauthorized access to video feeds and system configuration)
- **Integrity:** High (Modification of device settings and firmware)
- **Availability:** High (Potential to disable the device or cause a Denial of Service)
## Remediation
### Patches
- **Update to Version 6.0.0.66394 or later.** Johnson Controls recommends that users download the latest firmware from the Tyco/Illustra support portal.
### Workarounds
- **Network Segmentation:** Place affected devices on a secure, isolated VLAN.
- **Firewall Restrictions:** Ensure the devices are not accessible from the public internet and restrict access to authorized IP addresses only.
- **VPN Access:** Use a VPN for remote management of the devices rather than direct port forwarding.
## Detection
- **Indicators of Compromise:** Monitor for unusual administrative logins from unexpected IP addresses or unauthorized changes to system configuration settings.
- **Detection methods and tools:** Audit web server logs (if available) for malformed HTTP requests or repeated authentication attempts targeting administrative interfaces.
## References
- **Johnson Controls PSA:** hxxps[://]tyco[.]widen[.]net/s/gxrlcqnvn2/jci-psa-2026-37
- **JCI Trust Center:** hxxps[://]www[.]johnsoncontrols[.]com/trust-center/cybersecurity/security-advisories
- **Canadian Centre for Cyber Security:** hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/control-systems-johnson-controls-security-advisory-av26-1010