| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2022-21940 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in System Configuration Tool (SCT) | Johnson Controls | System Configuration Tool (SCT) | High | 7.5 | 2023-02-09 20:54:02 | Deep Dive |
| CVE-2022-21939 | Sensitive cookie without 'HttpOnly' flag in System Configuration Tool (SCT) | Johnson Controls | System Configuration Tool (SCT) | High | 7.5 | 2023-02-09 20:49:17 | Deep Dive |
| CVE-2021-36203 | Johnson Controls Metasys SCT Pro | Johnnson Controls | Metasys System Configuration Tool (SCT) | Medium | 5.3 | 2022-04-22 14:44:11 | Deep Dive |
| CVE-2020-9044 | Metasys Improper Restriction of XML External Entity Reference | Johnson Controls | Metasys Application and Data Server (ADS, ADS-Lite) | High | 7.5 | 2020-03-10 19:28:30 | Deep Dive |