VYPR

Istar Ultra Firmware

by Johnsoncontrols

CVEs (2)

  • CVE-2022-21941CriAug 31, 2022
    risk 0.65cvss 10.0epss 0.02

    All versions of iSTAR Ultra prior to version 6.8.9.CU01 are vulnerable to a command injection that could allow an unauthenticated user root access to the system.

  • CVE-2023-3127HigJul 11, 2023
    risk 0.49cvss 7.5epss 0.01

    An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.