ICSA-23-138-04: Johnson controls openblue enterprise manager data collector vulnerability
Affected Software
1 affected component
Johnson Controls Inc. OpenBlue Enterprise Manager Data Collector: Firmware versions prior to 3.2.5.75
Event History
Feb 22, 2025
Advisory Published
11:35 PM
Frequently Asked Questions
1
What is the severity of ICSA-23-138-04?
The vulnerability ICSA-23-138-04 has a critical severity rating, indicating significant risk to affected systems.
2
How do I fix ICSA-23-138-04?
To fix ICSA-23-138-04, upgrade the firmware of the Johnson Controls Inc. OpenBlue Enterprise Manager Data Collector to version 3.2.5.75 or later.
3
What systems are affected by ICSA-23-138-04?
ICSA-23-138-04 affects firmware versions prior to 3.2.5.75 of the Johnson Controls Inc. OpenBlue Enterprise Manager Data Collector.
4
What is the nature of the vulnerability in ICSA-23-138-04?
The vulnerability in ICSA-23-138-04 allows for unauthorized access, potentially compromising the integrity of the system.
5
When was ICSA-23-138-04 disclosed?
ICSA-23-138-04 was disclosed on June 14, 2023, by the Cybersecurity and Infrastructure Security Agency.