Where
-Infinity
0
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.

Remedy

Update SCT version 14 with patch 14.2.3

Remedy

Update SCT version 15 with patch 15.0.3

Remedy

Contact your local Johnson Controls office or Authorized Building Control Specialists (ABCS).
First published (updated )
Severity
7.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.

Remedy

Update SCT version 14 with patch 14.2.3

Remedy

Update SCT version 15 with patch 15.0.3

Remedy

Contact your local Johnson Controls office or Authorized Building Control Specialists (ABCS).
First published (updated )
Severity
9.1
SSRF
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

The affected product may allow an attacker to identify and forge requests to internal systems by way of a specially crafted request.

Remedy

Johnson Controls recommends users take the following steps to mitigate this vulnerability: Update SCT/SCT Pro with Patch 14.2.2 Take proper steps to minimize risks to all building automation systems. For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2022-03 v1
First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203