CVE-2023-2024: Johnsoncontrols Openblue Enterprise Manager Data Collector
High severity, CVSS 7.5. EPSS: 1.1% chance of exploitation in the next 30 days.
Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unauthorized user under certain circumstances.
Affected products
- Johnsoncontrols Openblue Enterprise Manager Data Collector: before 3.2.5.75 (fixed in 3.2.5.75)
Published 2023-05-18. Last modified 2026-06-17.