CVE-2024-32752

CRITICAL

Johnson Controls iSTAR Configuration Utility (ICU) - Unauthenticated Access to iSTAR Door Controllers

Title source: llm
STIX 2.1

Description

The iSTAR door controllers running firmware prior to version 6.6.B, does not support authenticated communications with ICU, which may allow an attacker to gain unauthorized access

Scores

CVSS v3 9.1
EPSS 0.0059
EPSS Percentile 43.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (3)
Johnson Controls/iSTAR Configuration Utility (ICU) < All
Johnson Controls/iSTAR Pro, Edge and eX < All
Johnson Controls/iSTAR Ultra and Ultra LT < 6.6.B
Published Jun 06, 2024
Tracked Since Feb 18, 2026