An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.
References
Link | Resource |
---|---|
https://www.cisa.gov/news-events/ics-advisories/icsa-23-192-02 | Third Party Advisory US Government Resource |
https://www.johnsoncontrols.com/cyber-solutions/security-advisories | Vendor Advisory |
https://www.cisa.gov/news-events/ics-advisories/icsa-23-192-02 | Third Party Advisory US Government Resource |
https://www.johnsoncontrols.com/cyber-solutions/security-advisories | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
History
21 Nov 2024, 08:16
Type | Values Removed | Values Added |
---|---|---|
References | () https://www.cisa.gov/news-events/ics-advisories/icsa-23-192-02 - Third Party Advisory, US Government Resource | |
References | () https://www.johnsoncontrols.com/cyber-solutions/security-advisories - Vendor Advisory | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
20 Jul 2023, 01:49
Type | Values Removed | Values Added |
---|---|---|
First Time |
Johnsoncontrols edge G2
Johnsoncontrols istar Ultra Lt Firmware Johnsoncontrols istar Ultra Lt Johnsoncontrols Johnsoncontrols istar Ultra Johnsoncontrols istar Ultra G2 Johnsoncontrols istar Ultra Firmware Johnsoncontrols edge G2 Firmware Johnsoncontrols istar Ultra G2 Firmware |
|
CWE | CWE-287 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
References | (MISC) https://www.cisa.gov/news-events/ics-advisories/icsa-23-192-02 - Third Party Advisory, US Government Resource | |
References | (MISC) https://www.johnsoncontrols.com/cyber-solutions/security-advisories - Vendor Advisory | |
CPE | cpe:2.3:h:johnsoncontrols:istar_ultra_lt:-:*:*:*:*:*:*:* cpe:2.3:o:johnsoncontrols:istar_ultra_g2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:johnsoncontrols:edge_g2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:johnsoncontrols:istar_ultra_g2_firmware:6.9.2:-:*:*:*:*:*:* cpe:2.3:o:johnsoncontrols:istar_ultra_firmware:6.9.2:-:*:*:*:*:*:* cpe:2.3:h:johnsoncontrols:istar_ultra_g2:-:*:*:*:*:*:*:* cpe:2.3:h:johnsoncontrols:istar_ultra:-:*:*:*:*:*:*:* cpe:2.3:h:johnsoncontrols:edge_g2:-:*:*:*:*:*:*:* cpe:2.3:o:johnsoncontrols:istar_ultra_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:johnsoncontrols:edge_g2_firmware:6.9.2:-:*:*:*:*:*:* cpe:2.3:o:johnsoncontrols:istar_ultra_lt_firmware:6.9.2:-:*:*:*:*:*:* cpe:2.3:o:johnsoncontrols:istar_ultra_lt_firmware:*:*:*:*:*:*:*:* |
11 Jul 2023, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-07-11 22:15
Updated : 2024-11-21 08:16
NVD link : CVE-2023-3127
Mitre link : CVE-2023-3127
CVE.ORG link : CVE-2023-3127
JSON object : View
Products Affected
johnsoncontrols
- istar_ultra
- istar_ultra_firmware
- edge_g2_firmware
- istar_ultra_g2_firmware
- istar_ultra_lt
- edge_g2
- istar_ultra_g2
- istar_ultra_lt_firmware
CWE
CWE-287
Improper Authentication