CVE-2023-2025

MEDIUM

Johnsoncontrols Openblue Enterprise M... - Information Disclosure

Title source: rule
STIX 2.1

Description

OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 may expose sensitive information to an unauthorized user under certain circumstances.

Scores

CVSS v3 5.0
EPSS 0.0014
EPSS Percentile 33.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-200 CWE-668
Status published
Products (1)
johnsoncontrols/openblue_enterprise_manager_data_collector < 3.2.5.75
Published May 18, 2023
Tracked Since Feb 18, 2026