Impact
The vulnerability resides in the on‑chip debug interface of the Neo Series MVP2. An attacker who can access the debug interface can collect data from common resource locations, potentially exposing sensitive information. The weakness aligns with CWE‑1191, indicating improper access control or insufficient restriction of debug capabilities, leading to unauthorized data exposure.
Affected Systems
The affected devices are Johnson Controls Neo Series MVP2 units running firmware versions prior to 3.3b63. No other vendor or product versions are listed as affected. The vulnerability does not appear to affect later releases, but verification against the latest firmware is recommended.
Risk and Exploitability
The CVSS base score of 7.2 classifies this as a high‑severity issue with significant confidentiality impact. EPSS information is unavailable, so the current exploitation likelihood cannot be quantified, but the absence of an KEV listing suggests no known widespread exploitation. The likely attack vector is local access to the on‑chip debug interface, implying that an attacker must have physical proximity or privileged network access to the device. In the absence of additional mitigations, possession of the debug interface grants the attacker read access to internal data.
OpenCVE Enrichment