First published: Wed Aug 31 2022(Updated: )
All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauthenticated user root access to the system.
Credit: productsecurity@jci.com
Affected Software | Affected Version | How to fix |
---|---|---|
Johnsoncontrols Istar Ultra Firmware | <6.8.9.cu01 | |
Johnsoncontrols Istar Ultra | ||
Sensormatic Electronics, a subsidiary of Johnson Controls Inc. iSTAR Ultra CU01 | <6.8.9. | 6.8.9. |
Upgrade iSTAR Ultra firmware to version 6.8.9.CU01. The firmware can be downloaded here: https://www.swhouse.com/Support/SoftwareDownloads.aspx
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-21941.
The severity of CVE-2022-21941 is critical with a severity value of 9.8.
All versions of iSTAR Ultra prior to version 6.8.9.CU01 are affected by CVE-2022-21941.
CVE-2022-21941 is a command injection vulnerability that could allow an unauthenticated user to gain root access to the system.
To fix CVE-2022-21941, upgrade iSTAR Ultra to version 6.8.9.CU01 or later.