# CVE-2024-0912

## Summary

- **CVE ID:** CVE-2024-0912
- **Severity:** HIGH
- **CVSS Score:** 8.5 (CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:L/SC:H/SI:H/SA:L)
- **CWE:** CWE-532
- **Published:** Jun 5, 2024
- **Last Modified:** Mar 13, 2026

## Description

Under certain circumstances the Microsoft® Internet Information Server (IIS) used to host the C•CURE 9000 Web Server will log Microsoft Windows credential details within logs. There is no impact to non-web service interfaces C•CURE 9000 or prior versions

## Affected Products

- Johnson Controls — Software House C•CURE 9000 (0)

## References

- [CNA](https://www.johnsoncontrols.com/-/media/jci/cyber-solutions/product-security-advisories/2024/jci-psa-2024-04.pdf)
- [CNA](https://www.cisa.gov/news-events/ics-advisories/icsa-24-135-03)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.16%
- **EPSS Percentile:** 5.9

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._