CVE-2023-2025

MEDIUM

Johnsoncontrols Openblue Enterprise M... - Information Disclosure

Title source: rule

Description

OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 may expose sensitive information to an unauthorized user under certain circumstances.

Scores

CVSS v3 5.0
EPSS 0.0013
EPSS Percentile 32.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

Classification

CWE
CWE-200 CWE-668
Status published

Affected Products (1)

johnsoncontrols/openblue_enterprise_manager_data_collector < 3.2.5.75

Timeline

Published May 18, 2023
Tracked Since Feb 18, 2026