CVE Published: 31/08/2022 |
CVE Updated: 17/09/2024 |
CVE Year: 2022 Source: jci |
Vendor: Johnson Controls |
Product: iSTAR Ultra Status : PUBLISHED
CVE-2022-21941 Description
All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauthenticated user root access to the system.
Metrics
CVSS Version: 3.1 |
Base Score: 10 CRITICAL Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H