Johnson Controls iSTAR Ultra
cpe:2.3:o:johnsoncontrols:istar_ultra_firmware:*:*:*:*:*:*:*, +1 more
- <= 6.9.2
An OS command injection vulnerability has been identified in the web application of Johnson Controls iSTAR Ultra products, including iSTAR Ultra SE and iSTAR Ultra G2. This vulnerability allows an authenticated attacker to execute commands on the device's operating system with 'root' privileges, potentially leading to unauthorized access or manipulation of the device firmware. The issue has been tested and confirmed on iSTAR Ultra firmware versions through 6.9.2, with later versions possibly also affected.
Exploitation of this vulnerability allows for authenticated command injection via HTTP, with injected OS commands executed as the 'root' user on the device.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.