Johnson Controls has an update available to handle sensitive cookie without ‘HttpOnly’ flag and sensitive cookie in HTTPS session without ‘secure’ attribute vulnerabilities in its System Configuration Tool, according to a report with CISA.

Successful exploitation of these remotely exploitable vulnerabilities, which Johnson Controls self-reported, could allow an attacker to access cookies and take over the user’s session.

The following versions of System Configuration Tool (SCT) suffer from the issue:

  • System Configuration Tool (SCT) version 14: Versions prior to 14.2.3
  • System Configuration Tool (SCT) version 15: Versions prior to 15.0.3

In one issue, System Configuration Tool (SCT) versions 14 and 15 are vulnerable during a cross-site scripting attack. This could allow an attacker to access cookies and take control of an affected system.

Schneider Bold

CVE-2022-21939 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 7.5.

In addition, System Configuration Tool (SCT) versions 14 and 15 are vulnerable during a cross-site scripting attack. This could allow an attacker to access cookies and take control of an affected system.

CVE-2022-21940 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 7.5.

The product sees use mainly in the critical manufacturing sector, and on a global basis.

No known public exploits specifically target these vulnerabilities. These vulnerabilities have a high attack complexity.

Johnson Controls recommends users take the following actions to mitigate the vulnerabilities.

  • Update SCT version 14 with patch 14.2.3
  • Update SCT version 15 with patch 15.0.3
  • Contact your local Johnson Controls office or Authorized Building Control Specialists (ABCS)
  • For more detailed mitigation instructions, click on Johnson Controls Product Security Advisory JCI-PSA-2022-07 v1
ISSSource

Pin It on Pinterest

Share This