CVE-2025-61736: iSTAR- Improper Validation of Certificate Expiration
Successful exploitation of this vulnerability could result in the product failing to re-establish communication once the certificate expires.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61736?
CVE-2025-61736 is categorized as a high severity vulnerability due to the risk of failed communication after certificate expiration.
How do I fix CVE-2025-61736?
To fix CVE-2025-61736, ensure that you upgrade to the latest version of the affected Johnson Controls products that support TLS 1.2.
What products are affected by CVE-2025-61736?
CVE-2025-61736 affects Johnson Controls iSTAR eX, iSTAR Edge, iSTAR Ultra LT, iSTAR Ultra, and iSTAR Ultra SE models prior to TLS 1.2.
What happens if CVE-2025-61736 is exploited?
Exploitation of CVE-2025-61736 can lead to a failure in re-establishing communication once the product's certificate expires.
Is there a temporary workaround for CVE-2025-61736?
Currently, there are no documented temporary workarounds for CVE-2025-61736, and upgrading to a secure version is recommended.