Johnson Controls OpenBlue Mobile Web Application for OpenBlue Workplace
ID: 8db25c3c-b8c8-54fd-be54-4e5dbae3fda0
STIX ID: report--8db25c3c-b8c8-54fd-be54-4e5dbae3fda0
Feed Name: All CISA Advisories
Threat Score
Johnson Controls and CISA published an advisory for CVE-2025-26381, a Direct Request ('Forced Browsing') vulnerability in OpenBlue Mobile Web Application (<= 2025.1.2) that may allow remote, low-complexity access to sensitive information; CVSS v3.1 is 9.3 (critical) and CVSS v4 is 6.5 (base), mitigations include upgrading to 2025.1.3 or disabling the mobile application in IIS and following CISA/Johnson Controls guidance.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
