iSTAR Ultra performs a firmware verification on boot, however the verification does not inspect certain portions of the firmware. These firmware parts may contain malicious code. Tested up to firmware 6.9.2, later firmwares are also possibly affected.
Metrics
Affected Vendors & Products
References
History
Tue, 29 Jul 2025 10:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Johnsoncontrols
Johnsoncontrols istar Ultra |
|
Vendors & Products |
Johnsoncontrols
Johnsoncontrols istar Ultra |
Mon, 28 Jul 2025 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 28 Jul 2025 15:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | iSTAR Ultra performs a firmware verification on boot, however the verification does not inspect certain portions of the firmware. These firmware parts may contain malicious code. Tested up to firmware 6.9.2, later firmwares are also possibly affected. | |
Weaknesses | CWE-494 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: Dragos
Published: 2025-07-28T14:43:01.059Z
Updated: 2025-07-28T17:57:40.745Z
Reserved: 2025-07-08T14:48:42.604Z
Link: CVE-2025-53696

Updated: 2025-07-28T15:25:04.049Z

Status : Awaiting Analysis
Published: 2025-07-28T15:15:26.670
Modified: 2025-07-29T14:14:29.590
Link: CVE-2025-53696

No data.