Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in System Configuration Tool (SCT)
CVE-2022-21940

7.5HIGH

Key Information:

Vendor
CVE Published:
9 February 2023

What is CVE-2022-21940?

A vulnerability exists in the Johnson Controls System Configuration Tool that allows sensitive cookie data to be accessed due to the absence of the 'Secure' attribute in HTTPS sessions. This flaw affects versions 14 and 15 of the tool, potentially exposing users to risks such as session hijacking or unauthorized access. It is crucial for users running affected versions to update and secure their configurations to mitigate risks.

Affected Version(s)

System Configuration Tool (SCT) 14 < 14.2.3

System Configuration Tool (SCT) 15 < 15.0.3

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2022-21940 : Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in System Configuration Tool (SCT)