ICSA-25-338-04: : Johnson Controls Inc. iSTAR eX: All versions prior to TLS 1.2 vulnerability
Affected Software
5 affected components
: Johnson Controls Inc. iSTAR eX: All versions prior to TLS 1.2
: Johnson Controls Inc. iSTAR Edge: All versions prior to TLS 1.2
: Johnson Controls Inc. iSTAR Ultra LT (if in TLS 1.2): All versions prior to TLS 1.2
: Johnson Controls Inc. iSTAR Ultra (if in TLS 1.2): All versions prior to TLS 1.2
: Johnson Controls Inc. iSTAR Ultra SE (if in TLS 1.2): All versions prior to TLS 1.2
Event History
Dec 17, 2025
Advisory Published
01:00 PM
Data Sourced
01:00 PM
Affected Software
Frequently Asked Questions
1
What is the severity of ICSA-25-338-04?
The ICSA-25-338-04 vulnerability is considered high severity due to the potential for unauthorized access and data interception.
2
How do I fix ICSA-25-338-04?
To fix ICSA-25-338-04, upgrade all affected Johnson Controls iSTAR devices to versions that support TLS 1.2.
3
What products are affected by ICSA-25-338-04?
ICSA-25-338-04 affects Johnson Controls iSTAR eX, Edge, Ultra LT, Ultra, and Ultra SE devices operating on versions prior to TLS 1.2.
4
What are the risks of not addressing ICSA-25-338-04?
Failure to address ICSA-25-338-04 can result in the exposure of sensitive data and increased vulnerability to cyber attacks.
5
Is there a patch available for ICSA-25-338-04?
Yes, a patch is available by upgrading to the latest versions of the affected Johnson Controls iSTAR devices that implement TLS 1.2.