No analysis available yet.
Vendor Solution
* Upgrade iSTAR Ultra, iSTAR Ultra SE, iStar Ultra LT to version 6.9.7.CU01 or greater. * Upgrade iSTAR Ultra G2, iSTAR Ultra G2 SE, iSTAR Edge G2 to version 6.9.3 or greater.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 18 Dec 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Johnsoncontrols
Johnsoncontrols edge G2 Johnsoncontrols istar Edge G2 Johnsoncontrols istar Ultra Johnsoncontrols istar Ultra G2 Johnsoncontrols istar Ultra G2 Se Johnsoncontrols istar Ultra Se |
|
| Vendors & Products |
Johnsoncontrols
Johnsoncontrols edge G2 Johnsoncontrols istar Edge G2 Johnsoncontrols istar Ultra Johnsoncontrols istar Ultra G2 Johnsoncontrols istar Ultra G2 Se Johnsoncontrols istar Ultra Se |
Wed, 17 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 17 Dec 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Successful exploitation of these vulnerabilities could allow an attacker to modify firmware and gain full access to the device. | |
| Title | iSTAR Ultra, Ultra SE, Ultra G2, Ultra G2 SE, iSTAR Edge G2 - Authenticated web application command injection - setFaultDebounce | |
| Weaknesses | CWE-78 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: jci
Published:
Updated: 2025-12-17T16:42:19.977Z
Reserved: 2025-04-17T20:07:25.122Z
Link: CVE-2025-43873
Updated: 2025-12-17T16:42:15.228Z
Status : Awaiting Analysis
Published: 2025-12-17T16:16:05.703
Modified: 2025-12-18T15:07:42.550
Link: CVE-2025-43873
No data.
OpenCVE Enrichment
Updated: 2025-12-18T09:57:32Z