CVE-2023-3127: Improper Authentication in iSTAR
An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, iSTAR Edge G2 firmwareto a version that resolves this vulnerability.Fixed in 6.9.2 CU01
Event History
Frequently Asked Questions
What is the severity of CVE-2023-3127?
The severity of CVE-2023-3127 is critical, with a severity value of 9.8.
Which software versions are affected by CVE-2023-3127?
The affected software versions are Johnsoncontrols iSTAR Ultra Firmware 6.8.6 to 6.9.2, iSTAR Ultra LT Firmware 6.8.6 to 6.9.2, iSTAR Ultra G2 Firmware up to 6.9.2, and iSTAR Edge G2 Firmware up to 6.9.2.
How can an unauthenticated user exploit CVE-2023-3127?
An unauthenticated user can exploit CVE-2023-3127 by logging into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.
Is Johnsoncontrols iSTAR Ultra vulnerable to CVE-2023-3127?
No, Johnsoncontrols iSTAR Ultra is not vulnerable to CVE-2023-3127.
Where can I find more information about CVE-2023-3127?
You can find more information about CVE-2023-3127 in the security advisories on the Johnson Controls website and the ICS-CERT website.