Smart Buildings at Risk: Critical Johnson Controls Flaw (CVSS 10) Allows Remote SQL Injection
ID: b85d2e89-cb9c-5246-a534-580ef6bfa7f4
STIX ID: report--b85d2e89-cb9c-5246-a534-580ef6bfa7f4
Feed Name: securityonline.info
Threat Score
CISA and Johnson Controls warn of CVE-2025-26385, a critical (CVSS 10) remote SQL-execution vulnerability in Metasys components (ADS/ADX, LCS8500/NAE8500, SCT, CCT) that could allow attackers to manipulate building automation data and controls; vendor patch GIV-165989 and network mitigation (block TCP/1433 and network segmentation per the Metasys hardening guide) are recommended.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
