CVE-2023-3127

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
11/07/2023
Last modified:
20/07/2023

Description

An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:johnsoncontrols:istar_ultra_firmware:*:*:*:*:*:*:*:* 6.8.6 (including) 6.9.2 (excluding)
cpe:2.3:o:johnsoncontrols:istar_ultra_firmware:6.9.2:-:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:istar_ultra:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:istar_ultra_lt_firmware:*:*:*:*:*:*:*:* 6.8.6 (including) 6.9.2 (excluding)
cpe:2.3:o:johnsoncontrols:istar_ultra_lt_firmware:6.9.2:-:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:istar_ultra_lt:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:istar_ultra_g2_firmware:*:*:*:*:*:*:*:* 6.9.2 (excluding)
cpe:2.3:o:johnsoncontrols:istar_ultra_g2_firmware:6.9.2:-:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:istar_ultra_g2:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:edge_g2_firmware:*:*:*:*:*:*:*:* 6.9.2 (excluding)
cpe:2.3:o:johnsoncontrols:edge_g2_firmware:6.9.2:-:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:edge_g2:-:*:*:*:*:*:*:*