Show filters
62 Total Results
Displaying 11-20 of 62
Sort by:
Attacker Value
Unknown

CVE-2023-4804

Disclosure Date: November 10, 2023 (last updated November 17, 2023)
An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.
Attacker Value
Unknown

CVE-2023-3749

Disclosure Date: August 03, 2023 (last updated October 08, 2023)
A local user could edit the VideoEdge configuration file and interfere with VideoEdge operation.
Attacker Value
Unknown

CVE-2023-3548

Disclosure Date: July 25, 2023 (last updated October 08, 2023)
An unauthorized user could gain account access to IQ Wifi 6 versions prior to 2.0.2 by conducting a brute force authentication attack.
Attacker Value
Unknown

CVE-2023-3127

Disclosure Date: July 11, 2023 (last updated October 08, 2023)
An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.
Attacker Value
Unknown

CVE-2023-0954

Disclosure Date: June 08, 2023 (last updated October 08, 2023)
A debug feature in Sensormatic Electronics Illustra Pro Gen 4 Dome and PTZ cameras allows a user to compromise credentials after a long period of sustained attack.
Attacker Value
Unknown

CVE-2023-2025

Disclosure Date: May 18, 2023 (last updated October 08, 2023)
OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 may expose sensitive information to an unauthorized user under certain circumstances.
Attacker Value
Unknown

CVE-2023-2024

Disclosure Date: May 18, 2023 (last updated October 08, 2023)
Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unauthorized user under certain circumstances.
Attacker Value
Unknown

CVE-2022-21940

Disclosure Date: February 09, 2023 (last updated October 08, 2023)
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.
Attacker Value
Unknown

CVE-2022-21939

Disclosure Date: February 09, 2023 (last updated October 08, 2023)
Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.
Attacker Value
Unknown

CVE-2021-36204

Disclosure Date: January 13, 2023 (last updated October 08, 2023)
Under some circumstances an Insufficiently Protected Credentials vulnerability in Johnson Controls Metasys ADS/ADX/OAS 10 versions prior to 10.1.6 and 11 versions prior to 11.0.3 allows API calls to expose credentials in plain text.