← Back to home
ICSA-25-146-01  ·  Published 2025-05-27  ·  View on CISA ICS-CERT ↗

Johnson Controls iSTAR Configuration Utility (ICU) tool

CVSS 7.4 HIGH

Risk Summary

Successful exploitation of this vulnerability may allow an attacker to gain access to memory leaked from the ICU. This utility is only used to configure products that are no longer manufactured or supported. ICU is not used to configure the iSTAR Ultra and the current iSTAR G2 series of controllers. Furthermore, this vulnerability only impacts ICU and the Windows PC it is running on. This vulnerability does not impact iSTARs, including the legacy iSTARs.

CVEs (1)

Remediations

  • Johnson Controls recommends users update ICU to Version 6.9.5 or greater.
  • For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2025-06
  • For assistance and additional information, please contact Johnson Controls Trust [email protected]

Affected Vendors

Johnson Controls Inc.

Affected Products (1)

Johnson Controls Inc. · ICU <6.9.5

Affected Sectors

Commercial Facilities, Critical Manufacturing, Energy, Government Services and Facilities, Transportation Systems

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more