All 2 CVE vulnerabilities found in System Configuration Tool (SCT), with AI-generated Chinese analysis, references, and POCs.
Vendor: Johnson Controls
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2022-21940 | Sensitive Cookie in HTTPS Session Without 'Secure' Attribute in System Configuration Tool (SCT) CWE-614 | 7.5 | High | 2023-02-09 |
| CVE-2022-21939 | Sensitive cookie without 'HttpOnly' flag in System Configuration Tool (SCT) CWE-1004 | 7.5 | High | 2023-02-09 |
All 2 known CVE vulnerabilities affecting System Configuration Tool (SCT) with full Chinese analysis, references, and POCs where available.