Home
HIGH: 7.2 CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:L/SI:L/SA:NDefault status
unaffected
IQ Panels2 (custom)
affected
IQ Panel 2+ (custom)
affected
IQHub (custom)
affected
IQPanel 4 (custom)
affected
PowerG (custom)
affected
Description
Use of a weak pseudo-random number generator, which may allow an attacker to read or inject encrypted PowerG packets.
Problem types
CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)
Product status
IQ Panels2 (custom)
IQ Panel 2+ (custom)
IQHub (custom)
IQPanel 4 (custom)
PowerG (custom)
Credits
James Chambersof NCC Group
and Sultan Qasim Khan NCC Group
References
www.johnsoncontrols.com/...cybersecurity/security-advisories
www.cisa.gov/news-events/ics-advisories/icsa-25-350-02
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.