[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$frH7tL-MsBny2ApCBfLUsz_lsosCJMnpuFHVQqzocL0A":3},{"lesson":4},{"id":5,"slug":6,"article_id":7,"title":8,"body":9,"prevention":10,"framework_refs":11,"status":22,"created_at":23,"published_at":24,"article":25,"tags":29,"podcasts":48},"5c90739d-7bb7-43a4-a158-7fea9a41b4f6","critical-rce-vulnerabilities-in-johnson-controls-physical-security-servers","3385129c-b7e4-415a-a391-c49601ac0a98","Critical RCE Vulnerabilities in Johnson Controls Physical Security Servers","Johnson Controls' C-CURE 9000 and Victor application servers contain critical vulnerabilities — including Server-Side Request Forgery (SSRF) and execution with unnecessary privileges — that allow unauthenticated attackers to achieve remote code execution without any credentials. This is especially dangerous because these systems manage physical security infrastructure, meaning a successful exploit could compromise access control systems, cameras, and facility security. The 'unnecessary privileges' flaw indicates that the application was not designed with the principle of least privilege, amplifying the blast radius of any successful attack. Physical security systems are often overlooked in traditional IT patch cycles, creating a dangerous blind spot in enterprise security posture.","**Immediate Actions:**\n- Upgrade all affected C-CURE 9000 and Victor instances to versions beyond v2.90\u002Fv3.0 and Victor Web beyond v7.1 immediately.\n- Isolate C-CURE 9000 and Victor servers behind strict firewall rules, blocking all unauthenticated external network access.\n- Audit service account privileges on these servers and enforce the principle of least privilege to reduce exploit impact.\n\n**Long-Term Improvements:**\n- Integrate physical security management systems (PSMS) into the enterprise vulnerability management and patch lifecycle program.\n- Implement network segmentation to place physical security servers in dedicated VLANs, separated from corporate IT and OT networks.\n- Enforce a zero-trust access model requiring authentication and authorization for all connections to physical security application servers.\n\n**Detection Measures:**\n- Deploy an intrusion detection\u002Fprevention system (IDS\u002FIPS) tuned to detect SSRF attack patterns targeting internal physical security infrastructure.\n- Enable and centralize logging for all authentication attempts and API calls on C-CURE 9000 and Victor servers, feeding into a SIEM for anomaly alerting.\n- Conduct regular vulnerability scans specifically targeting OT and physical security systems to identify unpatched or misconfigured assets proactively.",[12,13,14,15,16,17,18,19,20,21],"CIS Control 7: Continuous Vulnerability Management","CIS Control 4: Controlled Use of Administrative Privileges","CIS Control 12: Boundary Defense \u002F Network Segmentation","NIST SP 800-82: Guide to Industrial Control Systems Security","NIST AC-6: Least Privilege","NIST SI-2: Flaw Remediation","NIST SC-7: Boundary Protection","IEC 62443-3-3: System Security Requirements for Industrial Automation","ITIL Change Management: Emergency Change Procedures","CISA ICS-CERT Advisory Best Practices","published","2026-07-23T20:21:29.986871+00:00","2026-07-23T20:21:29.698+00:00",{"id":7,"url":26,"slug":27,"title":28},"https:\u002F\u002Fwww.cisa.gov\u002Fnews-events\u002Fics-advisories\u002Ficsa-26-204-01","johnson-controls-c-cure-9000-and-victor-application-server-d90c73","Johnson Controls C-CURE 9000 and Victor application server",[30,36,42],{"id":31,"name":32,"slug":33,"description":34,"color":35},"1ec88fde-2d0f-4ed8-932a-33f5ccc0fdc7","Access Control","access-control","Excessive privileges, missing MFA, weak auth","#f97316",{"id":37,"name":38,"slug":39,"description":40,"color":41},"af7fce9e-1ce8-4156-93bc-09dcfbfdf29d","Patch Management","patch-management","Unpatched vulnerabilities, delayed updates","#ef4444",{"id":43,"name":44,"slug":45,"description":46,"color":47},"f43a7f30-5046-4b10-9dba-1a704139821e","Network Segmentation","network-segmentation","Lateral movement, flat networks, missing firewalls","#06b6d4",[]]