Johnson Controls C-CURE 9000 and Victor application server
2026-07-23T19:23:28Z•2d9ae4ba5bafe21d17aca3b64cf4a661645b52a517699834c7432cfaeb980634
authentication bypassbuffer overflowc-cure 9000cisacleartext credentialscmt3092xcredential exposureicsintravuejohnson controlslib60870libiec61850mz automationotout-of-bounds readpanduitprivilege escalationpronetiqsrcessrftpdin-monitor-web2tycon systemsvictorweintekxaap android
What happened
CISA ICS advisory bundle describing multiple vulnerabilities across OT/ICS products from Johnson Controls, Weintek, Panduit/Pronetiqs, MZ Automation, Tycon Systems, and others. Issues include remote code execution and SSRF (C-CURE 9000 / Victor), authentication bypass, cleartext credential storage, privilege escalation, stack/heap buffer overflows, out-of-bounds reads, and denial-of-service conditions. Affected components span application servers, HMIs, protocol libraries (IEC 61850, IEC 60870), and web management interfaces with CVSS scores up to 10.0. Deployments are worldwide across several
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- cisa_ics_advisories
- Record identifier
- 2d9ae4ba5bafe21d17aca3b64cf4a661645b52a517699834c7432cfaeb980634
- Enrichment time
- 2026-07-23T19:23:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.