PatchSiren cyber security CVE debrief
CVE-2025-26382 Johnson Controls Inc. CVE debrief
CVE-2025-26382 is a Critical vulnerability in Johnson Controls Software House iSTAR Configuration Utility (ICU). CISA’s advisory says the ICU tool can have a buffer overflow issue under certain circumstances, and the affected product range is ICU versions earlier than 6.9.5. Johnson Controls recommends upgrading to ICU 6.9.5 or greater and following the vendor’s product security advisory for mitigation guidance. CISA published the advisory on 2025-04-24 and later issued a minor revision on 2025-05-06 that fixed typos.
- Vendor
- Johnson Controls Inc.
- Product
- ICU
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-04-24
- Original CVE updated
- 2025-05-06
- Advisory published
- 2025-04-24
- Advisory updated
- 2025-05-06
Who should care
Organizations that use Johnson Controls Software House iSTAR ICU, especially teams responsible for building automation, physical security, OT, and system administration, should prioritize this advisory. Any environment running ICU versions earlier than 6.9.5 should be treated as exposed until verified updated.
Technical summary
The advisory describes a buffer overflow affecting Johnson Controls ICU under certain circumstances. The associated CVSS v3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, with a score of 9.8, indicating a critical issue with high potential impact on confidentiality, integrity, and availability. The source corpus identifies ICU < 6.9.5 as affected and recommends upgrading to 6.9.5 or later.
Defensive priority
Immediate. This is a critical-severity vulnerability with a 9.8 CVSS score and a straightforward vendor remediation path. If ICU is present in your environment, confirm version status and plan upgrades quickly, especially for systems supporting operational or physical-security functions.
Recommended defensive actions
- Upgrade Johnson Controls ICU to version 6.9.5 or later as soon as feasible.
- Identify all systems running ICU and confirm whether any instance is earlier than 6.9.5.
- Review Johnson Controls Product Security Advisory JCI-PSA-2025-04 for detailed mitigation guidance.
- Apply the CISA-referenced industrial control system defensive practices appropriate to your environment.
- Treat unpatched ICU deployments as high priority until version status is verified and remediation is completed.
Evidence notes
Source evidence is limited to the supplied CISA CSAF advisory and the referenced official links. The corpus states: “Under certain circumstances, the ICU tool can have a buffer overflow issue.” It also identifies affected product scope as “Johnson Controls Inc. ICU: <6.9.5” and recommends upgrading to version 6.9.5 or greater. The advisory was initially published on 2025-04-24 and revised on 2025-05-06 for typo fixes only. No KEV entry is present in the supplied data.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-26382 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-26382
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-26382 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-26382
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-114-05.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-114-05
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.