CVE-2022-21940: Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in System Configuration Tool (SCT)
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.
Affected Software
Remediation
Information
Information
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-21940?
The severity of CVE-2022-21940 is high.
How does CVE-2022-21940 impact Johnson Controls System Configuration Tool (SCT)?
CVE-2022-21940 allows access to sensitive cookies in the HTTPS session without the 'Secure' attribute, which could compromise the security of the SCT.
Which versions of Johnson Controls System Configuration Tool (SCT) are affected by CVE-2022-21940?
Versions 14 prior to 14.2.3 and version 15 prior to 15.0.3 of Johnson Controls System Configuration Tool (SCT) are affected by CVE-2022-21940.
How can I fix CVE-2022-21940?
To fix CVE-2022-21940, it is recommended to update Johnson Controls System Configuration Tool (SCT) to version 14.2.3 or 15.0.3 or later.
Where can I find more information about CVE-2022-21940?
You can find more information about CVE-2022-21940 on the following resources: CISA website (https://www.cisa.gov/uscert/ics/advisories/icsa-23-040-03) and Johnson Controls Security Advisories (https://www.johnsoncontrols.com/cyber-solutions/security-advisories).