Lucene search

K
cvelistJciCVELIST:CVE-2023-3127
HistoryJul 11, 2023 - 9:06 p.m.

CVE-2023-3127 Improper Authentication in iSTAR

2023-07-1121:06:29
CWE-287
jci
www.cve.org
2
istar ultra
istar ultra lt
istar ultra g2
istar edge g2
improper authentication
administrator rights

CVSS3

7.5

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L

AI Score

9.7

Confidence

High

EPSS

0.003

Percentile

68.4%

An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "iSTAR Ultra",
    "vendor": "Sensormatic Electronics, a subsidiary of Johnson Controls, Inc.",
    "versions": [
      {
        "lessThan": "6.9.2 CU01",
        "status": "affected",
        "version": ">6.8.6",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "iSTAR Ultra LT",
    "vendor": "Sensormatic Electronics, a subsidiary of Johnson Controls, Inc.",
    "versions": [
      {
        "lessThan": "6.9.2 CU01",
        "status": "affected",
        "version": ">6.8.6",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "iSTAR Ultra G2",
    "vendor": "Sensormatic Electronics, a subsidiary of Johnson Controls, Inc.",
    "versions": [
      {
        "lessThan": "6.9.2 CU01",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  },
  {
    "defaultStatus": "unaffected",
    "product": "iSTAR Edge G2",
    "vendor": "Sensormatic Electronics, a subsidiary of Johnson Controls, Inc.",
    "versions": [
      {
        "lessThan": "6.9.2 CU01",
        "status": "affected",
        "version": "0",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

ADJACENT

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

HIGH

Availability Impact

LOW

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L

AI Score

9.7

Confidence

High

EPSS

0.003

Percentile

68.4%

Related for CVELIST:CVE-2023-3127