ICSA-25-345-02: : Johnson Controls iSTAR Ultra: Versions prior to 6.9.7.CU01 vulnerability
Affected Software
6 affected componentsFixes available
: Johnson Controls iSTAR Ultra: Versions prior to 6.9.7.CU01
: Johnson Controls iSTAR Ultra SE: Versions prior to 6.9.7.CU01
: Johnson Controls iSTAR Ultra LT: Versions prior to 6.9.7.CU01
: Johnson Controls iSTAR Ultra G2<6.9.3
6.9.3
: Johnson Controls iSTAR Ultra G2 SE<6.9.3
6.9.3
: Johnson Controls iSTAR Edge G2<6.9.3
6.9.3
Event History
Dec 17, 2025
Advisory Published
04:01 PM
Data Sourced
04:01 PM
Affected Software
Frequently Asked Questions
1
What is the severity of ICSA-25-345-02?
The severity of ICSA-25-345-02 is considered high due to the potential for unauthorized access and control of affected systems.
2
How do I fix ICSA-25-345-02?
To mitigate ICSA-25-345-02, users should upgrade the Johnson Controls iSTAR Ultra and related products to version 6.9.7.CU01 or later.
3
What systems are affected by ICSA-25-345-02?
ICSA-25-345-02 affects Johnson Controls iSTAR Ultra, iSTAR Ultra SE, iSTAR Ultra LT, iSTAR Ultra G2, iSTAR Ultra G2 SE, and iSTAR Edge G2 versions prior to 6.9.7.CU01.
4
What are the potential risks associated with ICSA-25-345-02?
The risks associated with ICSA-25-345-02 include unauthorized access, compromised system integrity, and potential security breaches.
5
Is there a workaround for ICSA-25-345-02?
There are no recommended workarounds for ICSA-25-345-02; the best course of action is to update the affected systems.