HIGH · 7.5

CVE-2023-3127

An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.

Vulnerability Description

An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L
Attack Vector
ADJACENT_NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
LOW
Integrity
HIGH
Availability
LOW

Affected Products

VendorProductVersions
JohnsoncontrolsIstar Ultra Firmware>= 6.8.6, < 6.9.2
JohnsoncontrolsIstar Ultra-
JohnsoncontrolsIstar Ultra Lt Firmware>= 6.8.6, < 6.9.2
JohnsoncontrolsIstar Ultra Lt-
JohnsoncontrolsIstar Ultra G2 Firmware< 6.9.2
JohnsoncontrolsIstar Ultra G2-
JohnsoncontrolsEdge G2 Firmware< 6.9.2
JohnsoncontrolsEdge G2-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-3127?

CVE-2023-3127 is a vulnerability with a CVSS score of 7.5 (HIGH). An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.

How severe is CVE-2023-3127?

CVE-2023-3127 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-3127?

Check the references section above for vendor advisories and patch information. Affected products include: Johnsoncontrols Istar Ultra Firmware, Johnsoncontrols Istar Ultra, Johnsoncontrols Istar Ultra Lt Firmware, Johnsoncontrols Istar Ultra Lt, Johnsoncontrols Istar Ultra G2 Firmware.