Description
Successful exploitation of these vulnerabilities could allow an attacker to modify firmware and gain full access to the device.
Problem types
CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Product status
Any version
Credits
Reid Wightman of Dragos reported these vulnerabilities to CISA.
References
www.johnsoncontrols.com/...cybersecurity/security-advisories
www.cisa.gov/news-events/ics-advisories/icsa-25-345-02
Data based on CVE®. Copyright © 1999-2025, The MITRE Corporation. All rights reserved.