CVE-2025-26382: Johnson Controls Software House iSTAR Configuration Utility (ICU) Tool
Published Apr 24, 2025
·Updated
Under certain circumstances the iSTAR Configuration Utility (ICU) tool could have a buffer overflow issue
Affected Software
2 affected componentsFixes available
: Johnson Controls Inc. ICU<6.9.5
6.9.5
iSTAR Configuration Utility (ICU)
Remediation
Information
Upgrade ICU to version 6.9.5 or greater
Event History
Apr 24, 2025
CVE Published
via MITRE·07:47 PM
Data Sourced
via MITRE·07:47 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-26382?
CVE-2025-26382 has a high severity rating due to the potential for a buffer overflow which could lead to arbitrary code execution.
2
How do I fix CVE-2025-26382?
To fix CVE-2025-26382, upgrade the iSTAR Configuration Utility to version 6.9.5 or later.
3
What vulnerabilities does CVE-2025-26382 address?
CVE-2025-26382 addresses a buffer overflow issue specifically in the iSTAR Configuration Utility.
4
Which versions of the iSTAR Configuration Utility are affected by CVE-2025-26382?
Versions of the iSTAR Configuration Utility prior to 6.9.5 are affected by CVE-2025-26382.
5
Who is the vendor responsible for CVE-2025-26382?
The vendor responsible for CVE-2025-26382 is Johnson Controls Inc.