Schwachstellen werden geladen…
Schwachstellen werden geladen…
CVE-2026-21653
Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery. This issue affects CCure 9000 and victor application server: from 2.9 through 3.0.
Dieser Datensatz: Live-Anbindung— zuletzt abgerufen: 24. September 2026 um 05:08.
Direkt aus NVD, CISA oder vom Hersteller übernommen — teils auf Englisch, unverändert gegenüber der Quelle.
Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery. This issue affects CCure 9000 and victor application server: from 2.9 through 3.0.
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Vector
NETWORK
Privileges Required
NONE
User Interaction
NONE
Vertraulichkeit
Keine
Integrität
Keine
Verfügbarkeit
Keine
Ausnutzungswahrscheinlichkeit innerhalb von 30 Tagen
0.4%
Perzentil
33e
Quelle: FIRST.org, aktualisiert am 23. September 2026.
Johnson Controls recommends the following defensive measures to help reduce the risk of exploitation. Johnson Controls recommends following both steps in the mitigation guidance. However, until an upgrade is completed, the defensive measures outlined will reduce the attack surface: Firewall / access control lists - Implement strict firewall rules to block all unnecessary inbound connections to port 8999 from untrusted network segments. Intrusion detection / prevention - Deploy IDS/IPS signatures tuned to detect known .NET deserialization exploit payloads (e.g., ysoserial.net patterns) targeting port 8999. Application whitelisting - Enforce application whitelisting on application server hosts to prevent unauthorized executables from being launched by the server process. Least privilege - Ensure the application server process runs with the minimum privileges necessary, reducing the impact of successful exploitation. Monitor and audit - Enable detailed logging on application server hosts and monitor for anomalous process creation by SoftwareHouse.CrossFire.Server.exe. Disable unnecessary services - If the ClientConnectionManager_NF.SynchronousServerNotification callback interface is not required, disable or restrict it to reduce attack surface.
Unsere eigene Einordnung und unser Kontext zu den obigen Quelldaten.
IACS-Radar-Einordnung
Unsere eigene Einordnung und unser Kontext zu dieser Schwachstelle — keine offizielle Quelle.
IACS-Radar-Prioritätswert
Basierend auf CVSS 9.6, EPSS 0.4%, industrielle Relevanz 40/100.
Kombiniert CVSS, EPSS, KEV-Status, industrielle Relevanz und Expositionsrelevanz — eine Ergänzung, kein Ersatz für die einzelnen Werte darunter und darüber.
Voraussetzungen für eine Ausnutzung
Operative Auswirkungen & Energierelevanz
Begrenzte Auswirkung auf die Verfügbarkeit; das Risiko liegt vor allem bei der Vertraulichkeit oder Integrität von Prozessdaten.
Keine starken energiesektorspezifischen Signale erkannt; allgemeine OT-/ICS-Relevanz.
Empfohlene defensive Maßnahmen
Industrieller Relevanzwert
Die Einstufung ist vorläufig; eine manuelle Überprüfung durch einen OT-Security-Analysten wird empfohlen.
Klassifiziert von IACS Radar-analysepijplijn (geautomatiseerd) am 24. September 2026.
IEC-62443-Zuordnung
Automatische IACS-Radar-Einordnung anhand der gemeldeten CWE-Schwächeklassifizierung; keine offizielle Zertifizierungsaussage.