CVE-2022-21940 Vulnerability Details

  /     /     /  

CVE-2022-21940 Metadata Quick Info

CVE Published: 09/02/2023 | CVE Updated: 03/08/2024 | CVE Year: 2022
Source: jci | Vendor: Johnson Controls | Product: System Configuration Tool (SCT)
Status : PUBLISHED

CVE-2022-21940 Description

Sensitive Cookie in HTTPS Session Without \'Secure\' Attribute vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.

Metrics

CVSS Version: 3.1 | Base Score: 7.5 HIGH
Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

l➤ Exploitability Metrics:
    Attack Vector (AV)* NETWORK
    Attack Complexity (AC)* HIGH
    Privileges Required (PR)* NONE
    User Interaction (UI)* REQUIRED
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* HIGH
    Integrity Impact (I)* HIGH
    Availability Impact (A)* HIGH

Weakness Enumeration (CWE)

CWE-ID: CWE-614
CWE Name: CWE-614: Sensitive Cookie in HTTPS Session Without Secure Attribute
Source: Johnson Controls

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-212
CAPEC Description: CAPEC-212 Functionality Misuse


Source: NVD (National Vulnerability Database).