This page lists publicly disclosed CVE vulnerabilities affecting johnsoncontrols istar_ultra_firmware (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2023-3127 | An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights. | [email protected] | 7.5 | 0.45% | 2023-07-11 | 2026-06-17 |
| CVE-2022-21941 | All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauthenticated user root access to the system. | [email protected] | 10.0 | 1.96% | 2022-08-31 | 2026-06-17 |