An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.
References
Link | Resource |
---|---|
https://www.cisa.gov/news-events/ics-advisories/icsa-23-192-02 | Third Party Advisory US Government Resource |
https://www.johnsoncontrols.com/cyber-solutions/security-advisories | Vendor Advisory |
https://www.cisa.gov/news-events/ics-advisories/icsa-23-192-02 | Third Party Advisory US Government Resource |
https://www.johnsoncontrols.com/cyber-solutions/security-advisories | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
History
21 Nov 2024, 08:16
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
References | () https://www.cisa.gov/news-events/ics-advisories/icsa-23-192-02 - Third Party Advisory, US Government Resource | |
References | () https://www.johnsoncontrols.com/cyber-solutions/security-advisories - Vendor Advisory |
20 Jul 2023, 01:49
Type | Values Removed | Values Added |
---|---|---|
First Time |
Johnsoncontrols edge G2
Johnsoncontrols istar Ultra Lt Firmware Johnsoncontrols istar Ultra Lt Johnsoncontrols Johnsoncontrols istar Ultra Johnsoncontrols istar Ultra G2 Johnsoncontrols istar Ultra Firmware Johnsoncontrols edge G2 Firmware Johnsoncontrols istar Ultra G2 Firmware |
|
CWE | CWE-287 | |
CPE | cpe:2.3:h:johnsoncontrols:istar_ultra_lt:-:*:*:*:*:*:*:* cpe:2.3:o:johnsoncontrols:istar_ultra_g2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:johnsoncontrols:edge_g2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:johnsoncontrols:istar_ultra_g2_firmware:6.9.2:-:*:*:*:*:*:* cpe:2.3:o:johnsoncontrols:istar_ultra_firmware:6.9.2:-:*:*:*:*:*:* cpe:2.3:h:johnsoncontrols:istar_ultra_g2:-:*:*:*:*:*:*:* cpe:2.3:h:johnsoncontrols:istar_ultra:-:*:*:*:*:*:*:* cpe:2.3:h:johnsoncontrols:edge_g2:-:*:*:*:*:*:*:* cpe:2.3:o:johnsoncontrols:istar_ultra_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:johnsoncontrols:edge_g2_firmware:6.9.2:-:*:*:*:*:*:* cpe:2.3:o:johnsoncontrols:istar_ultra_lt_firmware:6.9.2:-:*:*:*:*:*:* cpe:2.3:o:johnsoncontrols:istar_ultra_lt_firmware:*:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
References | (MISC) https://www.cisa.gov/news-events/ics-advisories/icsa-23-192-02 - Third Party Advisory, US Government Resource | |
References | (MISC) https://www.johnsoncontrols.com/cyber-solutions/security-advisories - Vendor Advisory |
11 Jul 2023, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-07-11 22:15
Updated : 2024-11-21 08:16
NVD link : CVE-2023-3127
Mitre link : CVE-2023-3127
CVE.ORG link : CVE-2023-3127
JSON object : View
Products Affected
johnsoncontrols
- istar_ultra_g2_firmware
- istar_ultra_g2
- istar_ultra_lt_firmware
- istar_ultra_lt
- istar_ultra
- edge_g2
- edge_g2_firmware
- istar_ultra_firmware
CWE
CWE-287
Improper Authentication