CVE-2022-21940: Johnsoncontrols Metasys System Configuration Tool
Medium severity, CVSS 6.1. EPSS: 0.4% chance of exploitation in the next 30 days.
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.
Affected products
- Johnsoncontrols Metasys System Configuration Tool: from 14.0, before 14.2.3 (fixed in 14.2.3); from 15.0, before 15.0.3 (fixed in 15.0.3)
Published 2023-02-09. Last modified 2026-06-17.