Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HJohnsoncontrols Metasys System Configuration Tool
APPJohnsoncontrols14.0 – 14.2.3 (excl.)15.0 – 15.0.3 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Related vulnerabilities
CVE-2022-21939HIGH7.5same product
Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) ver...
CVE-2020-9044HIGH7.5same product
XXE vulnerability exists in the Metasys family of product Web Services which has the potential to facilitate D...
CVE-2021-36203MEDIUM5.3same product
The affected product may allow an attacker to identify and forge requests to internal systems by way of a spec...
CVE-2024-32758CRITICAL9.0PL ✓same vendor
Niewystarczająca długość klucza kryptograficznego w komunikacji exacqVision
CVE-2023-4804CRITICAL10.0PL ✓same vendor
Niezamierzone ujawnienie funkcji debug w Johnson Controls Quantum HD Unity