Risk | Medium |
Patch available | YES |
Number of vulnerabilities | 1 |
CVE-ID | CVE-2023-3127 |
CWE-ID | CWE-287 |
Exploitation vector | Local network |
Public exploit | N/A |
Vulnerable software |
iSTAR Ultra Hardware solutions / Routers & switches, VoIP, GSM, etc iSTAR Ultra LT Hardware solutions / Routers & switches, VoIP, GSM, etc iSTAR Ultra G2 Hardware solutions / Routers & switches, VoIP, GSM, etc iSTAR Edge G2 Hardware solutions / Routers & switches, VoIP, GSM, etc |
Vendor | Sensormatic Electronics |
Security Bulletin
This security bulletin contains one medium risk vulnerability.
EUVDB-ID: #VU78237
Risk: Medium
CVSSv3.1: 6.5 [CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:L/I:H/A:L/E:U/RL:O/RC:C]
CVE-ID: CVE-2023-3127
CWE-ID:
CWE-287 - Improper Authentication
Exploit availability: No
DescriptionThe vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to an error in when processing authentication requests. A remote attacker on the local network can bypass authentication process and gain unauthorized access to the application.
MitigationInstall updates from vendor's website.
Vulnerable software versionsiSTAR Ultra: before 6.9.2 CU01
iSTAR Ultra LT: before 6.9.2 CU01
iSTAR Ultra G2: before 6.9.2 CU01
iSTAR Edge G2: before 6.9.2 CU01
CPE2.3http://www.johnsoncontrols.com/cyber-solutions/security-advisories
http://www.cisa.gov/news-events/ics-advisories/icsa-23-192-02
Q & A
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the local network (LAN).
How the attacker can exploit this vulnerability?
The attacker would have to send a specially crafted request to the affected device in order to exploit this vulnerability.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.