ZeroHour

CVE-2022-21940

CVSS 3.1
6.1 medium
EPSS
<1%p31
Published
()
Modified
Description

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.

Vendors
johnsoncontrols
Products
metasys system configuration tool
Weakness
CWE-614, CWE-311
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N

In the news

No ingested article mentions this CVE yet.