← Back to home
ICSA-25-345-02  ·  Published 2025-12-11  ·  View on CISA ICS-CERT ↗

Johnson Controls iSTAR Ultra

CVSS 8.8 HIGH

Risk Summary

Successful exploitation of these vulnerabilities could allow an attacker to modify firmware and gain full access to the device.

Remediations

  • Johnson Controls recommends users take the following actions:
  • Upgrade iSTAR Ultra, iSTAR Ultra SE, iSTAR Ultra LT to version 6.9.7.CU01 or greater.
  • Upgrade iSTAR Ultra G2, iSTAR Ultra G2 SE, iSTAR Edge G2 to version 6.9.3 or greater.
  • For more detailed mitigation instructions, please see Johnson Controls Product Security Advisory JCI-PSA-2025-11 and JCI-PSA-2025-13.
  • Johnson Controls recommends taking steps to minimize risks to all building automation systems in alignment with CISA's guidance.
  • Further ICS security notices and product security guidance are located at Johnson Controls product security website.
  • Organizations observing any suspected malicious activity should follow their established internal procedures and report their findings to CISA for tracking and correlation against other incidents.
  • For more information please contact Johnson Controls Global Product Security or visit their Cybersecurity page.

Affected Vendors

Johnson Controls

Affected Products (6)

Johnson Controls · iSTAR Ultra <6.9.7.CU01
Johnson Controls · iSTAR Ultra SE <6.9.7.CU01
Johnson Controls · iSTAR Ultra LT <6.9.7.CU01
Johnson Controls · iSTAR Ultra G2 <6.9.3
Johnson Controls · iSTAR Ultra G2 SE <6.9.3
Johnson Controls · iSTAR Edge G2 <6.9.3

Affected Sectors

Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more