Johnson Controls iSTAR Products Improper Certificate Expiration Validation Vulnerability

Vulnerability

A vulnerability exists in Johnson Controls iSTAR eX, iSTAR Edge, iSTAR Ultra LT, iSTAR Ultra, and iSTAR Ultra SE products, all versions prior to TLS 1.2. The issue arises from improper validation of certificate expiration, which can lead to communication failures with the C•CURE Server once the certificate expires.

Impact

Exploitation of this vulnerability can cause the product to stop communicating with the C•CURE Server after the certificate expires, disrupting normal operations.

Remediation

Johnson Controls recommends using host-based certificates with TLS 1.2, which requires downloading a new certificate to all iSTAR panels simultaneously. For iSTAR Ultra and Ultra SE panels, an upgrade to the new G2 hardware is recommended. Users can consult Johnson Controls' technical support and documentation for guidance on implementing these solutions.

Added: Dec 17, 2025, 1:20 PM
Updated: Dec 17, 2025, 1:20 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
0.6
exploitability
6.3
remediation
6.0
relevance
1.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.