CVE-2023-3127

An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.5 HIGH
ADJACENT_NETWORK
HIGH
NONE
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L
jciCNA
7.5 HIGH
ADJACENT_NETWORK
HIGH
NONE
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 34%
VendorProductVersion
johnsoncontrolsistar_ultra_firmware
6.8.6 ≤
𝑥
< 6.9.2
johnsoncontrolsistar_ultra_firmware
6.9.2
johnsoncontrolsistar_ultra_lt_firmware
6.8.6 ≤
𝑥
< 6.9.2
johnsoncontrolsistar_ultra_lt_firmware
6.9.2
johnsoncontrolsistar_ultra_g2_firmware
𝑥
< 6.9.2
johnsoncontrolsistar_ultra_g2_firmware
6.9.2
johnsoncontrolsedge_g2_firmware
𝑥
< 6.9.2
johnsoncontrolsedge_g2_firmware
6.9.2
𝑥
= Vulnerable software versions