Home
HIGH: 7.5 CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:LDefault status
unaffected
>6.8.6 (custom) before 6.9.2 CU01
affected
Default status
unaffected
>6.8.6 (custom) before 6.9.2 CU01
affected
Default status
unaffected
Any version before 6.9.2 CU01
affected
Default status
unaffected
Any version before 6.9.2 CU01
affected
Description
An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.
Problem types
CWE-287 Improper Authentication
Product status
>6.8.6 (custom) before 6.9.2 CU01
>6.8.6 (custom) before 6.9.2 CU01
Any version before 6.9.2 CU01
Any version before 6.9.2 CU01
References
www.johnsoncontrols.com/cyber-solutions/security-advisories
www.cisa.gov/news-events/ics-advisories/icsa-23-192-02
www.johnsoncontrols.com/cyber-solutions/security-advisories
www.cisa.gov/news-events/ics-advisories/icsa-23-192-02