Johnson Controls OpenBlue Employee
ID: c7eb423c-ce5f-5e81-8208-bf369060c7f8
STIX ID: report--c7eb423c-ce5f-5e81-8208-bf369060c7f8
Feed Name: CISA Advisories
Threat Score
CISA published an advisory for Johnson Controls OpenBlue Employee (<=V2025.3.1) describing multiple web application vulnerabilities — unrestricted file upload (CWE-434), stored XSS (CWE-79), and HTML/script-related injection (CWE-80) — that could allow attackers to upload malicious files or inject persistent malicious content; the report lists affected sectors worldwide, provides mitigation guidance, and states no known public exploitation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
