Johnson Controls Vulnerabilities and Affected Products
Vulnerabilities associated with IQ Panels2, 2+, IQHub, IQPanel 4, PowerG.
Products
Clear product- exacqVision6 vulnerabilities
- Frick Controls Quantum HD6 vulnerabilities
- Metasys ADS/ADX/OAS server6 vulnerabilities
- American Dynamics Illustra Essentials Gen 44 vulnerabilities
- iSTAR Configuration Utility (ICU)4 vulnerabilities
- Metasys4 vulnerabilities
- exacqVision Web Service3 vulnerabilities
- FM Systems Employee3 vulnerabilities
- IQ Panels2, 2+, IQHub, IQPanel 4, PowerG3 vulnerabilities
- iSTAR Ultra G2, iSTAR Ultra G2 SE, iSTAR Edge G22 vulnerabilities
- iSTAR Ultra, iSTAR Ultra SE2 vulnerabilities
- Metasys versions prior to 9.02 vulnerabilities
- OpenBlue Enterprise Manager Data Collector2 vulnerabilities
- Software House C•CURE 90002 vulnerabilities
- System Configuration Tool (SCT)2 vulnerabilities
- American Dynamics victor Video Management System v5.21 vulnerability
- BCPro (BCM)1 vulnerability
- C-CURE 90001 vulnerability
- CCure 90001 vulnerability
- CCure 9000 and victor application server1 vulnerability
- CEM Systems AC20001 vulnerability
- CEVAS1 vulnerability
- C•CURE 90001 vulnerability
- C•CURE Web Client version 2.90 and prior (Note - This does not affect the new web-based C•CURE 9000 client that was introduced in C•CURE 9000 v2.90)1 vulnerability
- Entrapass1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2025-61740HIGH | Johnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG Origin Validation ErrorAuthentication issue that does not verify the source of a packet which could allow an attacker to create a denial-of-service condition or modify the configuration of the device. CWE-346Dec 22, 2025 | CVSS7.2v4.0 | EPSS0.123% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-26379HIGH | Johnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG use of Cryptographically Weak Pseudo-Random Number GeneratorUse of a weak pseudo-random number generator, which may allow an attacker to read or inject encrypted PowerG packets. CWE-338Dec 22, 2025 | CVSS7.2v4.0 | EPSS0.166% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-61739HIGH | Johnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG reusing a nonce, key pair in encryptionDue to Nonce reuse, attackers can perform reply attack or decrypt captured packets. CWE-323Dec 22, 2025 | CVSS7.2v4.0 | EPSS0.166% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |