Impact
The vulnerability is a deserialization flaw (CWE-502) that occurs in Johnson Controls products when they accept serialized data from untrusted sources. An attacker can supply crafted objects to the Victor server on Windows, the CCure 9000 platform, or the Victor Application Server, potentially allowing execution of arbitrary code or other serious compromise of confidentiality, integrity, or availability. The weakness conforms to Capec-586 and is described as enabling unauthorized deserialization of data.
Affected Systems
Johnson Controls Victor server on Windows is vulnerable in all releases before version 8.0. The CCure 9000 platform is affected in installations earlier than 3.2. The Victor Application Server is impacted for versions earlier than 4.1. These products are affected by the deserialization of untrusted data flaw.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity vulnerability, and although the EPSS score is less than 1% (suggesting a low probability of exploitation, it is not zero). The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves an attacker who can supply or inject serialized objects to the server, possibly via HTTP or another interface, to trigger the flaw.
OpenCVE Enrichment