CVE-2024-5539: Automated Logic Webctrl
Critical severity, CVSS 9.2. EPSS: 0.3% chance of exploitation in the next 30 days.
The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in versions up to and including 8.5 allows a malicious actor to bypass intended access restrictions and expose sensitive information via the web based building automation server.
Affected products
- Automated Logic Webctrl: up to and including 8.5
- Carrier I-Vu: up to and including 8.5
Published 2025-11-27. Last modified 2026-06-17.