CVE-2022-21941: iSTAR Ultra
Published Aug 31, 2022
·Updated
All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauthenticated user root access to the system.
Affected Software
3 affected componentsFixes available
Sensormatic Electronics, a subsidiary of Johnson Controls Inc. iSTAR Ultra CU01<6.8.9.
6.8.9.
Johnsoncontrols Istar Ultra Firmware<6.8.9.cu01
Johnsoncontrols Istar Ultra
Remediation
Information
Upgrade iSTAR Ultra firmware to version 6.8.9.CU01. The firmware can be downloaded here: https://www.swhouse.com/Support/SoftwareDownloads.aspx
Event History
Aug 31, 2022
CVE Published
via MITRE·03:59 PM
Data Sourced
via MITRE·03:59 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-21941.
2
What is the severity of CVE-2022-21941?
The severity of CVE-2022-21941 is critical with a severity value of 9.8.
3
Which versions of iSTAR Ultra are affected by CVE-2022-21941?
All versions of iSTAR Ultra prior to version 6.8.9.CU01 are affected by CVE-2022-21941.
4
How does CVE-2022-21941 vulnerability work?
CVE-2022-21941 is a command injection vulnerability that could allow an unauthenticated user to gain root access to the system.
5
How can I fix CVE-2022-21941?
To fix CVE-2022-21941, upgrade iSTAR Ultra to version 6.8.9.CU01 or later.