An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.
References
Link | Resource |
---|---|
https://www.johnsoncontrols.com/cyber-solutions/security-advisories | Vendor Advisory |
https://www.cisa.gov/news-events/ics-advisories/icsa-23-192-02 | Third Party Advisory US Government Resource |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
History
20 Jul 2023, 01:49
Type | Values Removed | Values Added |
---|---|---|
First Time |
Johnsoncontrols istar Ultra G2
Johnsoncontrols istar Ultra Lt Firmware Johnsoncontrols istar Ultra Johnsoncontrols istar Ultra G2 Firmware Johnsoncontrols Johnsoncontrols edge G2 Firmware Johnsoncontrols edge G2 Johnsoncontrols istar Ultra Lt Johnsoncontrols istar Ultra Firmware |
|
CPE | cpe:2.3:o:johnsoncontrols:edge_g2_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:johnsoncontrols:istar_ultra_lt:-:*:*:*:*:*:*:* cpe:2.3:o:johnsoncontrols:istar_ultra_lt_firmware:6.9.2:-:*:*:*:*:*:* cpe:2.3:o:johnsoncontrols:istar_ultra_firmware:6.9.2:-:*:*:*:*:*:* cpe:2.3:o:johnsoncontrols:edge_g2_firmware:6.9.2:-:*:*:*:*:*:* cpe:2.3:h:johnsoncontrols:edge_g2:-:*:*:*:*:*:*:* cpe:2.3:o:johnsoncontrols:istar_ultra_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:johnsoncontrols:istar_ultra_g2_firmware:6.9.2:-:*:*:*:*:*:* cpe:2.3:h:johnsoncontrols:istar_ultra:-:*:*:*:*:*:*:* cpe:2.3:h:johnsoncontrols:istar_ultra_g2:-:*:*:*:*:*:*:* cpe:2.3:o:johnsoncontrols:istar_ultra_g2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:johnsoncontrols:istar_ultra_lt_firmware:*:*:*:*:*:*:*:* |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
CWE | CWE-287 | |
References | (MISC) https://www.johnsoncontrols.com/cyber-solutions/security-advisories - Vendor Advisory | |
References | (MISC) https://www.cisa.gov/news-events/ics-advisories/icsa-23-192-02 - Third Party Advisory, US Government Resource |
11 Jul 2023, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-07-11 22:15
Updated : 2023-07-20 01:49
NVD link : CVE-2023-3127
Mitre link : CVE-2023-3127
JSON object : View
Products Affected
johnsoncontrols
- istar_ultra_g2_firmware
- istar_ultra_lt_firmware
- istar_ultra_g2
- istar_ultra
- istar_ultra_firmware
- edge_g2_firmware
- edge_g2
- istar_ultra_lt
CWE
CWE-287
Improper Authentication