Metrics
Affected Vendors & Products
No advisories yet.
Solution
a. Update IQ Panel 4’s to version 4.6.1/4.6.1i b. Devices that support PowerG+ should use PowerG v53.05 or later. c. During the installation or enrollment of PowerG+ devices, enter the PIN code in the PIN Code field on the sensor enrollment screen. For additional security, Johnson Controls recommends only authorized company personnel or integrators be present during the pairing process d. Replace all End-of-Life Products (IQ Panel 2, IQ Panel 2+, IQ Hub) with the latest IQ Panel 4 using firmware version 4.6.1 or greater
Workaround
No workaround given by the vendor.
Mon, 22 Dec 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 22 Dec 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Authentication issue that does not verify the source of a packet which could allow an attacker to create a denial-of-service condition or modify the configuration of the device. | |
| Title | Johnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG Origin Validation Error | |
| Weaknesses | CWE-346 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: jci
Published:
Updated: 2025-12-22T16:20:04.536Z
Reserved: 2025-09-30T15:51:17.096Z
Link: CVE-2025-61740
Updated: 2025-12-22T16:20:00.515Z
Status : Received
Published: 2025-12-22T15:16:00.397
Modified: 2025-12-22T15:16:00.397
Link: CVE-2025-61740
No data.
OpenCVE Enrichment
No data.