CVE Vulnerabilities

CVE-2023-3127

Improper Authentication

Published: Jul 11, 2023 | Modified: Nov 21, 2024
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
Istar_ultra_firmwareJohnsoncontrols6.8.6 (including)6.9.2 (excluding)
Istar_ultra_firmwareJohnsoncontrols6.9.2 (including)6.9.2 (including)

Potential Mitigations

References