Known vulnerabilities in Metasys System Configuration Tool (SCT)
Vendor:
Johnson Controls
Software:
Metasys System Configuration Tool (SCT)
Software CPE:
cpe:2.3:a:johnson_controls:metasys_system_configuration_tool_sct:*:*:*:*:*:*:*:*
Website:
https://www.johnsoncontrols.com/
Total vulnerabilities:
4
Public exploits:
0
Known exploited (KEV):
0
Highest CVSSv4 Score:
8.8
Breakdown by Severity Chart
Vulnerabilities (4)
| Vulnerability | CWE-ID | CSH Severity | Public Exploit | KEV | First fixed release | Published | Bulletins |
|---|---|---|---|---|---|---|---|
| #VU72112 - Sensitive Cookie in HTTPS Session Without 'Secure' Attribute CVE-2022-21940 |
CWE-614 | Low | 14.2.3, 15.0.3 | 10.02.2023 |
SB2023021019 |
||
| #VU72111 - Sensitive Cookie Without 'HttpOnly' Flag CVE-2022-21939 |
CWE-1004 | Low | 14.2.3, 15.0.3 | 10.02.2023 |
SB2023021019 |
||
| #VU62489 - Server-Side Request Forgery (SSRF) CVE-2021-36203 |
CWE-918 | Medium | 14.2.2 | 22.04.2022 |
SB2022042203 |
||
| #VU25987 - Improper Restriction of XML External Entity Reference ('XXE') CVE-2020-9044 |
CWE-611 | High | - | 11.03.2020 |
SB2020031122 |