CVE-2023-3127

An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.
References
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:istar_ultra_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:istar_ultra_firmware:6.9.2:-:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:istar_ultra:-:*:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:istar_ultra_lt_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:istar_ultra_lt_firmware:6.9.2:-:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:istar_ultra_lt:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:istar_ultra_g2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:istar_ultra_g2_firmware:6.9.2:-:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:istar_ultra_g2:-:*:*:*:*:*:*:*

Configuration 4 (hide)

AND
OR cpe:2.3:o:johnsoncontrols:edge_g2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:edge_g2_firmware:6.9.2:-:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:edge_g2:-:*:*:*:*:*:*:*

History

20 Jul 2023, 01:49

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CWE CWE-287
References (MISC) https://www.cisa.gov/news-events/ics-advisories/icsa-23-192-02 - (MISC) https://www.cisa.gov/news-events/ics-advisories/icsa-23-192-02 - Third Party Advisory, US Government Resource
References (MISC) https://www.johnsoncontrols.com/cyber-solutions/security-advisories - (MISC) https://www.johnsoncontrols.com/cyber-solutions/security-advisories - Vendor Advisory
CPE cpe:2.3:h:johnsoncontrols:istar_ultra_g2:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:istar_ultra_g2_firmware:6.9.2:-:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:istar_ultra_firmware:6.9.2:-:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:edge_g2:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:istar_ultra_lt_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:istar_ultra_g2_firmware:*:*:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:istar_ultra_lt:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:edge_g2_firmware:6.9.2:-:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:istar_ultra_firmware:*:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:istar_ultra_lt_firmware:6.9.2:-:*:*:*:*:*:*
cpe:2.3:h:johnsoncontrols:istar_ultra:-:*:*:*:*:*:*:*
cpe:2.3:o:johnsoncontrols:edge_g2_firmware:*:*:*:*:*:*:*:*
First Time Johnsoncontrols istar Ultra Lt Firmware
Johnsoncontrols istar Ultra Firmware
Johnsoncontrols istar Ultra G2
Johnsoncontrols istar Ultra Lt
Johnsoncontrols istar Ultra G2 Firmware
Johnsoncontrols istar Ultra
Johnsoncontrols edge G2 Firmware
Johnsoncontrols
Johnsoncontrols edge G2

11 Jul 2023, 22:15

Type Values Removed Values Added
New CVE

Information

Published : 2023-07-11 22:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-3127

Mitre link : CVE-2023-3127

CVE.ORG link : CVE-2023-3127


JSON object : View

Products Affected

johnsoncontrols

  • istar_ultra_lt_firmware
  • istar_ultra
  • istar_ultra_g2
  • istar_ultra_lt
  • edge_g2
  • istar_ultra_firmware
  • edge_g2_firmware
  • istar_ultra_g2_firmware
CWE
CWE-287

Improper Authentication