An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.
References
Link | Resource |
---|---|
https://www.cisa.gov/news-events/ics-advisories/icsa-23-192-02 | Third Party Advisory US Government Resource |
https://www.johnsoncontrols.com/cyber-solutions/security-advisories | Vendor Advisory |
Configurations
Configuration 1 (hide)
AND |
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
History
20 Jul 2023, 01:49
Type | Values Removed | Values Added |
---|---|---|
First Time |
Johnsoncontrols istar Ultra Firmware
Johnsoncontrols istar Ultra Lt Johnsoncontrols edge G2 Johnsoncontrols istar Ultra G2 Johnsoncontrols edge G2 Firmware Johnsoncontrols istar Ultra Johnsoncontrols istar Ultra Lt Firmware Johnsoncontrols istar Ultra G2 Firmware Johnsoncontrols |
|
CWE | CWE-287 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.8 |
CPE | cpe:2.3:o:johnsoncontrols:istar_ultra_g2_firmware:6.9.2:-:*:*:*:*:*:* cpe:2.3:h:johnsoncontrols:istar_ultra:-:*:*:*:*:*:*:* cpe:2.3:h:johnsoncontrols:edge_g2:-:*:*:*:*:*:*:* cpe:2.3:o:johnsoncontrols:istar_ultra_lt_firmware:6.9.2:-:*:*:*:*:*:* cpe:2.3:o:johnsoncontrols:istar_ultra_lt_firmware:*:*:*:*:*:*:*:* cpe:2.3:h:johnsoncontrols:istar_ultra_lt:-:*:*:*:*:*:*:* cpe:2.3:h:johnsoncontrols:istar_ultra_g2:-:*:*:*:*:*:*:* cpe:2.3:o:johnsoncontrols:edge_g2_firmware:6.9.2:-:*:*:*:*:*:* cpe:2.3:o:johnsoncontrols:istar_ultra_g2_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:johnsoncontrols:istar_ultra_firmware:*:*:*:*:*:*:*:* cpe:2.3:o:johnsoncontrols:istar_ultra_firmware:6.9.2:-:*:*:*:*:*:* cpe:2.3:o:johnsoncontrols:edge_g2_firmware:*:*:*:*:*:*:*:* |
|
References | (MISC) https://www.cisa.gov/news-events/ics-advisories/icsa-23-192-02 - Third Party Advisory, US Government Resource | |
References | (MISC) https://www.johnsoncontrols.com/cyber-solutions/security-advisories - Vendor Advisory |
11 Jul 2023, 22:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-07-11 22:15
Updated : 2024-02-28 20:13
NVD link : CVE-2023-3127
Mitre link : CVE-2023-3127
CVE.ORG link : CVE-2023-3127
JSON object : View
Products Affected
johnsoncontrols
- istar_ultra_g2
- istar_ultra_lt
- edge_g2_firmware
- istar_ultra_g2_firmware
- istar_ultra_firmware
- istar_ultra_lt_firmware
- istar_ultra
- edge_g2
CWE
CWE-287
Improper Authentication