CVE-2022-21940
Summary
| CVE | CVE-2022-21940 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-02-09 21:15:00 UTC |
| Updated | 2023-06-27 18:19:00 UTC |
| Description | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie. |
Risk And Classification
Problem Types: CWE-311
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Johnsoncontrols | Metasys System Configuration Tool | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Johnson Controls System Configuration Tool (SCT) | CISA | MISC | www.cisa.gov | |
| Product Security Advisories | MISC | www.johnsoncontrols.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.