CVE-2023-3127

An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:istar_ultra_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:istar_ultra_firmware:6.9.2:-:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:istar_ultra:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:istar_ultra_lt_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:istar_ultra_lt_firmware:6.9.2:-:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:istar_ultra_lt:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:istar_ultra_g2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:istar_ultra_g2_firmware:6.9.2:-:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:istar_ultra_g2:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:edge_g2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:edge_g2_firmware:6.9.2:-:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:edge_g2:-:*:*:*:*:*:*:*

History

21 Nov 2024, 08:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : 9.8
v2 : unknown
v3 : 7.5
References () https://www.cisa.gov/news-events/ics-advisories/icsa-23-192-02 - Third Party Advisory, US Government Resource () https://www.cisa.gov/news-events/ics-advisories/icsa-23-192-02 - Third Party Advisory, US Government Resource
References () https://www.johnsoncontrols.com/cyber-solutions/security-advisories - Vendor Advisory () https://www.johnsoncontrols.com/cyber-solutions/security-advisories - Vendor Advisory

20 Jul 2023, 01:49

Type Values Removed Values Added
First Time Johnsoncontrols edge G2
Johnsoncontrols istar Ultra Lt Firmware
Johnsoncontrols istar Ultra Lt
Johnsoncontrols
Johnsoncontrols istar Ultra
Johnsoncontrols istar Ultra G2
Johnsoncontrols istar Ultra Firmware
Johnsoncontrols edge G2 Firmware
Johnsoncontrols istar Ultra G2 Firmware
CWE CWE-287
CPE cpe:2.3:h:johnsoncontrols:istar_ultra_lt:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:istar_ultra_g2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:edge_g2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:istar_ultra_g2_firmware:6.9.2:-:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:istar_ultra_firmware:6.9.2:-:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:istar_ultra_g2:-:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:istar_ultra:-:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:edge_g2:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:istar_ultra_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:edge_g2_firmware:6.9.2:-:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:istar_ultra_lt_firmware:6.9.2:-:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:istar_ultra_lt_firmware:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References (MISC) https://www.cisa.gov/news-events/ics-advisories/icsa-23-192-02 - (MISC) https://www.cisa.gov/news-events/ics-advisories/icsa-23-192-02 - Third Party Advisory, US Government Resource
References (MISC) https://www.johnsoncontrols.com/cyber-solutions/security-advisories - (MISC) https://www.johnsoncontrols.com/cyber-solutions/security-advisories - Vendor Advisory

11 Jul 2023, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-11 22:15

Updated : 2024-11-21 08:16


NVD link : CVE-2023-3127

Mitre link : CVE-2023-3127

CVE.ORG link : CVE-2023-3127


JSON object : View

Products Affected

johnsoncontrols

  • istar_ultra_g2_firmware
  • istar_ultra_g2
  • istar_ultra_lt_firmware
  • istar_ultra_lt
  • istar_ultra
  • edge_g2
  • edge_g2_firmware
  • istar_ultra_firmware
CWE
CWE-287

Improper Authentication