CVE-2023-3127
Severity CVSS v4.0:
Pending analysis
Type:
CWE-287
Authentication Issues
Publication date:
11/07/2023
Last modified:
20/07/2023
Description
An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:johnsoncontrols:istar_ultra_firmware:*:*:*:*:*:*:*:* | 6.8.6 (including) | 6.9.2 (excluding) |
| cpe:2.3:o:johnsoncontrols:istar_ultra_firmware:6.9.2:-:*:*:*:*:*:* | ||
| cpe:2.3:h:johnsoncontrols:istar_ultra:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:johnsoncontrols:istar_ultra_lt_firmware:*:*:*:*:*:*:*:* | 6.8.6 (including) | 6.9.2 (excluding) |
| cpe:2.3:o:johnsoncontrols:istar_ultra_lt_firmware:6.9.2:-:*:*:*:*:*:* | ||
| cpe:2.3:h:johnsoncontrols:istar_ultra_lt:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:johnsoncontrols:istar_ultra_g2_firmware:*:*:*:*:*:*:*:* | 6.9.2 (excluding) | |
| cpe:2.3:o:johnsoncontrols:istar_ultra_g2_firmware:6.9.2:-:*:*:*:*:*:* | ||
| cpe:2.3:h:johnsoncontrols:istar_ultra_g2:-:*:*:*:*:*:*:* | ||
| cpe:2.3:o:johnsoncontrols:edge_g2_firmware:*:*:*:*:*:*:*:* | 6.9.2 (excluding) | |
| cpe:2.3:o:johnsoncontrols:edge_g2_firmware:6.9.2:-:*:*:*:*:*:* | ||
| cpe:2.3:h:johnsoncontrols:edge_g2:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



