Johnson Controls has an update available to handle sensitive cookie without ‘HttpOnly’ flag and sensitive cookie in HTTPS session without ‘secure’ attribute vulnerabilities in its System Configuration Tool, according to a report with CISA.
Successful exploitation of these remotely exploitable vulnerabilities, which Johnson Controls self-reported, could allow an attacker to access cookies and take over the user’s session.
The following versions of System Configuration Tool (SCT) suffer from the issue:
- System Configuration Tool (SCT) version 14: Versions prior to 14.2.3
- System Configuration Tool (SCT) version 15: Versions prior to 15.0.3
In one issue, System Configuration Tool (SCT) versions 14 and 15 are vulnerable during a cross-site scripting attack. This could allow an attacker to access cookies and take control of an affected system.
CVE-2022-21939 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 7.5.
In addition, System Configuration Tool (SCT) versions 14 and 15 are vulnerable during a cross-site scripting attack. This could allow an attacker to access cookies and take control of an affected system.
CVE-2022-21940 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 7.5.
The product sees use mainly in the critical manufacturing sector, and on a global basis.
No known public exploits specifically target these vulnerabilities. These vulnerabilities have a high attack complexity.
Johnson Controls recommends users take the following actions to mitigate the vulnerabilities.
- Update SCT version 14 with patch 14.2.3
- Update SCT version 15 with patch 15.0.3
- Contact your local Johnson Controls office or Authorized Building Control Specialists (ABCS)
- For more detailed mitigation instructions, click on Johnson Controls Product Security Advisory JCI-PSA-2022-07 v1

