iSTAR Ultra performs a firmware verification on boot, however the verification does not inspect certain portions of the firmware. These firmware parts may contain malicious code. Tested up to firmware 6.9.2, later firmwares are also possibly affected.
Metrics
Affected Vendors & Products
References
History
Tue, 29 Jul 2025 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Johnsoncontrols
Johnsoncontrols istar Ultra |
|
| Vendors & Products |
Johnsoncontrols
Johnsoncontrols istar Ultra |
Mon, 28 Jul 2025 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 28 Jul 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | iSTAR Ultra performs a firmware verification on boot, however the verification does not inspect certain portions of the firmware. These firmware parts may contain malicious code. Tested up to firmware 6.9.2, later firmwares are also possibly affected. | |
| Weaknesses | CWE-494 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Dragos
Published: 2025-07-28T14:43:01.059Z
Updated: 2025-08-19T14:43:13.549Z
Reserved: 2025-07-08T14:48:42.604Z
Link: CVE-2025-53696
Updated: 2025-07-28T15:25:04.049Z
Status : Awaiting Analysis
Published: 2025-07-28T15:15:26.670
Modified: 2025-07-29T14:14:29.590
Link: CVE-2025-53696
No data.