First published: Thu May 18 2023(Updated: )
OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 may expose sensitive information to an unauthorized user under certain circumstances.
Credit: productsecurity@jci.com
Affected Software | Affected Version | How to fix |
---|---|---|
Johnsoncontrols Openblue Enterprise Manager Data Collector | <3.2.5.75 | |
Johnson Controls Inc. OpenBlue Enterprise Manager Data Collector: Firmware versions prior to 3.2.5.75 |
Update all OpenBlue Enterprise Manager Data Collector firmware to version 3.2.5.75.
Contact your Customer Success Manager to obtain the update.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this CVE is CVE-2023-2025.
The severity of CVE-2023-2025 is medium with a severity value of 6.5.
OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 are affected by CVE-2023-2025.
An unauthorized user can exploit CVE-2023-2025 to gain access to sensitive information under certain circumstances.
You can find more information about CVE-2023-2025 on the CISA website and the Johnson Controls security advisories.