Impact
Johnson Controls T2000 air‑control units expose a debug and test interface with insufficient access control, permitting an attacker with physical access or authorized service credentials to interact with proprietary functions that are meant to be protected. This flaw can allow the attacker to read configuration data, alter device settings, or misuse the system for illicit purposes. The improper ACL enforcement on the debug port is the root weakness that can lead to unauthorized use of internal features.
Affected Systems
The affected firmware is any T2000 device running a version older than 31.6, which includes all pre‑31.6 releases. All devices of the T2000 family shipped with those firmware versions are vulnerable. No patch is available for firmware earlier than 31.6, so any remaining units must be updated or hardware replaced.
Risk and Exploitability
The CVSS vector of 5.2 indicates a moderate impact, and no EPSS data is available, suggesting limited evidence of active exploitation. The vulnerability is not listed in the CISA KEV, implying it has not been identified as a high‑risk or known exploited flaw. Attackers would likely need physical proximity to the debug port or compromise legitimate service credentials, which reduces the attack surface in purely remote scenarios but still poses significant risk for installations with inadequate physical security.
OpenCVE Enrichment