CVE-2022-21939 Vulnerability Details

  /     /     /  

CVE-2022-21939 Metadata Quick Info

CVE Published: 09/02/2023 | CVE Updated: 03/08/2024 | CVE Year: 2022
Source: jci | Vendor: Johnson Controls | Product: System Configuration Tool (SCT)
Status : PUBLISHED

CVE-2022-21939 Description

Sensitive Cookie Without \'HttpOnly\' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.

Metrics

CVSS Version: 3.1 | Base Score: 7.5 HIGH
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

l➤ Exploitability Metrics:
    Attack Vector (AV)* NETWORK
    Attack Complexity (AC)* HIGH
    Privileges Required (PR)* NONE
    User Interaction (UI)* REQUIRED
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* HIGH
    Integrity Impact (I)* HIGH
    Availability Impact (A)* HIGH

Weakness Enumeration (CWE)

CWE-ID: CWE-1004
CWE Name: CWE-1004: Sensitive Cookie Without HttpOnly Flag
Source: Johnson Controls

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-212
CAPEC Description: CAPEC-212 Functionality Misuse


Source: NVD (National Vulnerability Database).