CVE-2025-53696

CRITICAL

iSTAR Ultra - Info Disclosure

Title source: llm
STIX 2.1

Description

iSTAR Ultra performs a firmware verification on boot, however the verification does not inspect certain portions of the firmware. These firmware parts may contain malicious code. Tested up to firmware 6.9.2, later firmwares are also possibly affected.

Scores

CVSS v4 9.3
EPSS 0.0001
EPSS Percentile 3.1%
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-494
Status published
Products (1)
Johnson Controls, Inc/iSTAR Ultra < 6.9.2
Published Jul 28, 2025
Tracked Since Feb 18, 2026