Description
An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.
Problem types
CWE-287 Improper Authentication
Product status
>6.8.6 (custom) before 6.9.2 CU01
>6.8.6 (custom) before 6.9.2 CU01
Any version before 6.9.2 CU01
Any version before 6.9.2 CU01
References
www.johnsoncontrols.com/cyber-solutions/security-advisories
www.cisa.gov/news-events/ics-advisories/icsa-23-192-02