Description
iSTAR Ultra performs a firmware verification on boot, however the verification does not inspect certain portions of the firmware. These firmware parts may contain malicious code. Tested up to firmware 6.9.2, later firmwares are also possibly affected.
Scores
CVSS v4
9.3
EPSS
0.0001
EPSS Percentile
3.1%
CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-494
Status
published
Products (1)
Johnson Controls, Inc/iSTAR Ultra
< 6.9.2
Published
Jul 28, 2025
Tracked Since
Feb 18, 2026