AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-21940

HIGH · CVSS 7.5 EPSS 0.37%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-02-09 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. See the original NVD description below for full technical details.

CVE
CVE-2022-21940
Severity
HIGH
CVSS
7.5
EPSS
0.37%

Original NVD Description

Sensitive Cookie in HTTPS Session Without 'Secure' Attribute vulnerability in Johnson Controls System Configuration Tool (SCT) version 14 prior to 14.2.3 and version 15 prior to 15.0.3 could allow access to the cookie.

Related CVEs

Other vulnerabilities affecting the same vendor(s)