PT-2024-24827 · Johnson Controls · Kt1+2

Published

2024-07-04

·

Updated

2024-08-19

·

CVE-2024-32754

CVSS v3.1

3.1

Low

VectorAV:A/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions KT1, KT2, and KT400 controllers (affected versions not specified)
Description The issue concerns the broadcasting of sensitive information when the controller is in factory reset mode. Specifically, the controller broadcasts its MAC address, serial number, and firmware version under certain circumstances. This behavior stops once the controller is configured. There is no mention of the estimated number of potentially affected devices worldwide or details about real-world incidents where this issue was exploited.
Recommendations Update to safer versions as advised by Johnson Controls to protect against the potential exposure of private data when resetting to factory settings. As a temporary workaround, consider restricting access to the controller when it is in factory reset mode to minimize the risk of exploitation.

Fix

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2024-32754

Affected Products

Kt1
Kt2
Kt400