CVE-2025-43874: OS Command Injection
Affected Software
6 affected componentsFixes available
: Johnson Controls iSTAR Ultra: Versions prior to 6.9.7.CU01
: Johnson Controls iSTAR Ultra SE: Versions prior to 6.9.7.CU01
: Johnson Controls iSTAR Ultra LT: Versions prior to 6.9.7.CU01
: Johnson Controls iSTAR Ultra G2<6.9.3
6.9.3
: Johnson Controls iSTAR Ultra G2 SE<6.9.3
6.9.3
: Johnson Controls iSTAR Edge G2<6.9.3
6.9.3
Event History
Dec 17, 2025
CVE Published
via ICS·04:01 PM
Data Sourced
via ICS·04:01 PM
SeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-43874?
CVE-2025-43874 has a risk score of 83, indicating a high severity level.
2
What types of software are affected by CVE-2025-43874?
CVE-2025-43874 affects various versions of Johnson Controls iSTAR Ultra, iSTAR Ultra SE, iSTAR Ultra LT, iSTAR Ultra G2, iSTAR Ultra G2 SE, and iSTAR Edge G2.
3
How do I fix CVE-2025-43874?
To fix CVE-2025-43874, upgrade to versions 6.9.7.CU01 or later of the affected Johnson Controls software.
4
What is the nature of the vulnerability in CVE-2025-43874?
CVE-2025-43874 is an OS Command Injection vulnerability that could allow an attacker to execute arbitrary commands on the operating system.
5
Can CVE-2025-43874 be exploited remotely?
Yes, CVE-2025-43874 can potentially be exploited remotely, posing a significant security risk to affected systems.