ICSA-25-345-01: : Johnson Controls Inc. iSTAR Ultra: Versions prior to 6.9.7.CU01 vulnerability
Affected Software
5 affected componentsFixes available
: Johnson Controls Inc. iSTAR Ultra: Versions prior to 6.9.7.CU01
: Johnson Controls Inc. iSTAR Ultra SE: Versions prior to 6.9.7.CU01
: Johnson Controls Inc. iSTAR Ultra G2<6.9.3
6.9.3
: Johnson Controls Inc. iSTAR Ultra G2 SE<6.9.3
6.9.3
: Johnson Controls Inc. iSTAR Edge G2<6.9.3
6.9.3
Event History
Dec 24, 2025
Advisory Published
03:27 PM
Data Sourced
03:27 PM
Affected Software
Frequently Asked Questions
1
What is the severity of ICSA-25-345-01?
The severity of ICSA-25-345-01 is rated as high due to potential unauthorized access to sensitive information.
2
How do I fix ICSA-25-345-01?
To fix ICSA-25-345-01, upgrade the affected Johnson Controls iSTAR Ultra products to version 6.9.7.CU01 or later.
3
What products are affected by ICSA-25-345-01?
ICSA-25-345-01 affects Johnson Controls iSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, and Edge G2 versions prior to 6.9.7.CU01.
4
What type of vulnerability is identified in ICSA-25-345-01?
ICSA-25-345-01 identifies a software vulnerability that can lead to security breaches if left unpatched.
5
Is there a workaround for ICSA-25-345-01?
There are no official workarounds for ICSA-25-345-01; the recommended action is to apply the security update.