Sensitive cookie without 'HttpOnly' flag in System Configuration Tool (SCT)
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 0.5%
exploitation probability
0.5%top 56% of all CVEs
observed exploitation
nono source reports it
In short
The System Configuration Tool stores sensitive cookies without the HttpOnly flag, allowing attackers to steal them through JavaScript attacks. This puts user sessions at risk of unauthorized access.
Technical detail
CWE-1004 vulnerability in Johnson Controls SCT versions 14.x <14.2.3 and 15.x <15.0.3 exposes sensitive session cookies lacking HttpOnly protection, enabling client-side script injection (XSS) to exfiltrate authentication tokens and hijack authenticated sessions.
Summary generated and translated by AI from the official description.
Sensitive Cookie Without 'HttpOnly' Flag vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected products
Johnson Controls · System Configuration Tool (SCT)