Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in System Configuration Tool (SCT)
CVE-2022-21940
7.5HIGH
What is CVE-2022-21940?
A vulnerability exists in the Johnson Controls System Configuration Tool that allows sensitive cookie data to be accessed due to the absence of the 'Secure' attribute in HTTPS sessions. This flaw affects versions 14 and 15 of the tool, potentially exposing users to risks such as session hijacking or unauthorized access. It is crucial for users running affected versions to update and secure their configurations to mitigate risks.
Affected Version(s)
System Configuration Tool (SCT) 14 < 14.2.3
System Configuration Tool (SCT) 15 < 15.0.3
