CVE-2022-21941

Severity CVSS v4.0:
Pending analysis
Type:
CWE-77 Command Injection
Publication date:
31/08/2022
Last modified:
01/10/2022

Description

All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauthenticated user root access to the system.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:johnsoncontrols:istar_ultra_firmware:*:*:*:*:*:*:*:* 6.8.9.cu01 (excluding)
cpe:2.3:h:johnsoncontrols:istar_ultra:-:*:*:*:*:*:*:*