Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

Johnson Controls — Vulnerabilities & Security Advisories 101

Browse all 101 CVE security advisories affecting Johnson Controls. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Johnson Controls operates as a global leader in building technologies, providing integrated solutions for heating, ventilation, air conditioning, and security systems. With 76 recorded Common Vulnerabilities and Exposures (CVEs), the company’s software ecosystem has historically been susceptible to remote code execution, cross-site scripting, and privilege escalation flaws. These vulnerabilities often stem from legacy components within its building management platforms, exposing critical infrastructure to potential unauthorized access or data exfiltration. While no single catastrophic public breach has defined its recent history, the sheer volume of disclosed CVEs highlights systemic challenges in securing interconnected industrial control systems. Security researchers frequently identify these weaknesses as entry points for lateral movement within enterprise networks. Consequently, maintaining rigorous patch management and network segmentation remains essential for mitigating risks associated with Johnson Controls’ extensive hardware and software footprint in commercial and industrial environments.

CVE ID Title CVSS Severity Published
CVE-2026-21654 Johnson Controls -Frick Quantum HD- Unauthenticated Remote Code Execution — Frick Controls Quantum HD CWE-78 6.6 - 2026-02-27
CVE-2025-26385 Metasys product command injection vulnerability could allow remote SQL execution — Metasys CWE-77 9.8AI Critical AI 2026-01-30
CVE-2025-26386 Stack-based Buffer Overflow in Johnson Controls iSTAR Configuration Utility (ICU) tool — iSTAR Configuration Utility (ICU) CWE-121 8.4AI High AI 2026-01-28
CVE-2025-43876 iSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, iSTAR Edge G2 - Authenticated web application command injection - get8021xSettings — iSTAR Ultra, iSTAR Ultra SE CWE-78 9.8AI Critical AI 2025-12-24
CVE-2025-43875 iSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, iSTAR Edge G2 - Authenticated web application command injection - getOptionsInfo — iSTAR Ultra, iSTAR Ultra SE CWE-78 8.8AI High AI 2025-12-24
CVE-2025-61740 Johnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG Origin Validation Error — IQ Panels2, 2+, IQHub, IQPanel 4, PowerG CWE-346 9.1AI Critical AI 2025-12-22
CVE-2025-26379 Johnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG use of Cryptographically Weak Pseudo-Random Number Generator — IQ Panels2, 2+, IQHub, IQPanel 4, PowerG CWE-338 8.2AI High AI 2025-12-22
CVE-2025-61739 Johnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG reusing a nonce, key pair in encryption — IQ Panels2, 2+, IQHub, IQPanel 4, PowerG CWE-323 7.5AI High AI 2025-12-22
CVE-2025-61738 Johnson Controls PowerG and IQPanel cleartext transmission of sensitive information — IQPanel2, IQHub,IQPanel2+,IQPanel 4,PowerG CWE-319 7.4AI High AI 2025-12-22
CVE-2025-26381 OpenBlue Mobile Web Application configuration issue for optional for OpenBlue Workplace (formerly FM Systems) — OpenBlue Workplace (formerly FM Systems) CWE-425 7.5AI High AI 2025-12-17
CVE-2025-61736 iSTAR- Improper Validation of Certificate Expiration — iSTAReX, iSTAR Edge, iSTAR Ultra LT, iSTAR Ultra , iSTAR Ultra SE CWE-298 5.3AI Medium AI 2025-12-17
CVE-2025-26383 Johnson Controls iSTAR Configuration Utility 安全漏洞 — iSTAR Configuration Utility (ICU) CWE-457 5.5AI Medium AI 2025-06-11
CVE-2025-26382 Johnson Controls Software House iSTAR Configuration Utility (ICU) Tool — iSTAR Configuration Utility (ICU) CWE-121 8.4 - 2025-04-24
CVE-2024-32862 exacqVision CORS — exacqVision CWE-942 6.8 Medium 2024-08-01
CVE-2024-32758 exacqVision - Key exchanges — exacqVision CWE-326 - - AI 2024-08-01
CVE-2024-32931 exacqVison - Token Disclosed in URL — exacqVision CWE-598 5.7 Medium 2024-08-01
CVE-2024-32865 exacqVison - TLS certificate validation — exacqVision CWE-295 6.4 Medium 2024-08-01
CVE-2024-32864 exacqVison - HTTPS Session Establishment — exacqVision CWE-319 6.4 Medium 2024-08-01
CVE-2024-32863 exacqVison - CSRF issues with Web Service — exacqVision CWE-352 6.8 Medium 2024-08-01
CVE-2024-32861 Software House C•CURE - CouchDB executable protection — Software House C•CURE 9000 Installer CWE-276 7.8 High 2024-07-16
CVE-2024-32753 TYCO Illustra Pro Gen 4 - JQuery version — TYCO Illustra Pro4 Fixed cameras CWE-1395 9.1AI Critical AI 2024-07-11
CVE-2024-32759 Johnson Controls Software House C●CURE 9000 installer password strength — Software House C•CURE 9000 CWE-1391 9.8AI Critical AI 2024-07-10
CVE-2024-32754 Johnson Controls Kantech KT1, KT2, and KT400 Door Controllers - Exposure of Sensitive Information — Kantech KT1 Door Controller, Rev01 CWE-200 3.1 Low 2024-07-04
CVE-2024-32932 American Dynamics Illustra Essentials Gen 4 - Reversible User Credential - stored web interface — American Dynamics Illustra Essentials Gen 4 CWE-257 6.8 Medium 2024-07-02
CVE-2024-32757 American Dynamics Illustra Essentials Gen 4 - Linux Credential Leak — American Dynamics Illustra Essentials Gen 4 CWE-532 6.8 Medium 2024-07-02
CVE-2024-32756 American Dynamics Illustra Essentials Gen 4 - Reversible User Credential - Linux — American Dynamics Illustra Essentials Gen 4 CWE-257 6.8 Medium 2024-07-02
CVE-2024-32755 American Dynamics Illustra Essentials Gen 4 - Log Filter Input Validation — American Dynamics Illustra Essentials Gen 4 CWE-20 9.1 Critical 2024-07-02
CVE-2024-32752 Johnson Controls Software House iSTAR Configuration Utility (ICU) Tool — iSTAR Configuration Utility (ICU) CWE-306 8.1AI High AI 2024-06-06
CVE-2024-0912 CCURE passwords exposed to administrators — Software House C•CURE 9000 CWE-532 7.5AI High AI 2024-06-05
CVE-2023-4486 Uncontrolled Resource Consumption in Metasys and Facility Explorer — Metasys NAE55/SNE/SNC CWE-400 7.5 High 2023-12-07

This page lists every published CVE security advisory associated with Johnson Controls. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.