First published: Thu Feb 09 2023(Updated: )
Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.
Credit: productsecurity@jci.com
Affected Software | Affected Version | How to fix |
---|---|---|
Johnsoncontrols Metasys System Configuration Tool | >=14.0<14.2.3 | |
Johnsoncontrols Metasys System Configuration Tool | >=15.0<15.0.3 | |
Johnson Controls System Configuration Tool (SCT) version 14 | <14.2.3 | 14.2.3 |
Johnson Controls System Configuration Tool (SCT) version 15 | <15.0.3 | 15.0.3 |
Update SCT version 14 with patch 14.2.3
Update SCT version 15 with patch 15.0.3
Contact your local Johnson Controls office or Authorized Building Control Specialists (ABCS).
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-21939 is a vulnerability in Johnson Controls System Configuration Tool (SCT) versions 14.0 to 14.2.3 and versions 15.0 to 15.0.3.
The severity of CVE-2022-21939 is high with a CVSS score of 6.1.
CVE-2022-21939 is a Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) that could allow unauthorized access to the cookie.
Johnson Controls System Configuration Tool (SCT) versions 14 prior to 14.2.3 and versions 15 prior to 15.0.3 are affected by CVE-2022-21939.
To fix CVE-2022-21939, update Johnson Controls System Configuration Tool (SCT) to version 14.2.3 or 15.0.3 or later.