Showing 3 vulnerabilities on this page for IQ Panels2, 2+, IQHub, IQPanel 4, PowerG

Signals CISA KEV Ransomware Nuclei
Johnson Controls vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Johnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG Origin Validation Error

Authentication issue that does not verify the source of a packet which could allow an attacker to create a denial-of-service condition or modify the configuration of the device.

CWE-346Dec 22, 2025
CVSS7.2v4.0EPSS0.123%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Johnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG use of Cryptographically Weak Pseudo-Random Number Generator

Use of a weak pseudo-random number generator, which may allow an attacker to read or inject encrypted PowerG packets.

CWE-338Dec 22, 2025
CVSS7.2v4.0EPSS0.166%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

Johnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG reusing a nonce, key pair in encryption

Due to Nonce reuse, attackers can perform reply attack or decrypt captured packets.

CWE-323Dec 22, 2025
CVSS7.2v4.0EPSS0.166%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX