ICSA-25-146-01
·
Published 2025-05-27
·
View on CISA ICS-CERT ↗
Johnson Controls iSTAR Configuration Utility (ICU) tool
CVSS 7.4
HIGH
Risk Summary
Successful exploitation of this vulnerability may allow an attacker to gain access to memory leaked from the ICU. This utility is only used to configure products that are no longer manufactured or supported. ICU is not used to configure the iSTAR Ultra and the current iSTAR G2 series of controllers. Furthermore, this vulnerability only impacts ICU and the Windows PC it is running on. This vulnerability does not impact iSTARs, including the legacy iSTARs.
CVEs (1)
Remediations
- Johnson Controls recommends users update ICU to Version 6.9.5 or greater.
- For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2025-06
- For assistance and additional information, please contact Johnson Controls Trust [email protected]
Affected Vendors
Johnson Controls Inc.
Affected Products (1)
Johnson Controls Inc.
·
ICU
<6.9.5
Affected Sectors
Commercial Facilities, Critical Manufacturing, Energy, Government Services and Facilities, Transportation Systems
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more