6.1
CVSSv3

CVE-2022-21940

Published: 09/02/2023 Updated: 27/06/2023
CVSS v3 Base Score: 6.1 | Impact Score: 2.7 | Exploitability Score: 2.8
VMScore: 0

Vulnerability Summary

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 before 14.2.3 and version 15 before 15.0.3 could allow access to the cookie.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

johnsoncontrols metasys system configuration tool

ICS Advisories