Description
Debug and Test Interface With Improper Access Control vulnerability in Johnson Controls T2000 allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects T2000: before 31.6.
Published: 2026-08-27
Score: 5.2 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized access to the debug interface of Johnson Controls T2000 devices
Action: Apply Mitigation
AI Analysis

Impact

Johnson Controls T2000 air‑control units expose a debug and test interface with insufficient access control, permitting an attacker with physical access or authorized service credentials to interact with proprietary functions that are meant to be protected. This flaw can allow the attacker to read configuration data, alter device settings, or misuse the system for illicit purposes. The improper ACL enforcement on the debug port is the root weakness that can lead to unauthorized use of internal features.

Affected Systems

The affected firmware is any T2000 device running a version older than 31.6, which includes all pre‑31.6 releases. All devices of the T2000 family shipped with those firmware versions are vulnerable. No patch is available for firmware earlier than 31.6, so any remaining units must be updated or hardware replaced.

Risk and Exploitability

The CVSS vector of 5.2 indicates a moderate impact, and no EPSS data is available, suggesting limited evidence of active exploitation. The vulnerability is not listed in the CISA KEV, implying it has not been identified as a high‑risk or known exploited flaw. Attackers would likely need physical proximity to the debug port or compromise legitimate service credentials, which reduces the attack surface in purely remote scenarios but still poses significant risk for installations with inadequate physical security.

Generated by OpenCVE AI on August 28, 2026 at 07:19 UTC.

Remediation

Vendor Workaround

If immediate update is not possible, Johnson Controls recommends the following mitigations:  * Restrict physical access to the device by installing it in a secured equipment room that limits access to authorized service personnel only.  * Implement tamper-evident seals on device housings and panel enclosures to detect and deter unauthorized physical access attempts.  * Conduct periodic physical inspections of device installations to identify signs of tampering, unauthorized cable connections, or enclosure breaches.  Additional best-practice mitigations that end users can apply as a layer of defense:  * Physically secure the device enclosure to prevent unauthorized access to internal circuit boards and ports.  * Implement authentication mechanisms on any accessible debug interfaces to restrict access to authorized service personnel only.  * Monitor physical access to device installations and implement tamper detection where possible.  * Follow the recommendations in the Johnson Controls Product Hardening Guide available at  https://www.johnsoncontrols.com/trust-center/cybersecurity/resources .  These mitigations reduce risk but may not fully remediate the vulnerability.


OpenCVE Recommended Actions

  • Upgrade the T2000 firmware to version 31.6 or later to apply the vendor fix.
  • Limit physical access to the device by placing it in a secured room and restricting entry to authorized personnel only.
  • Install tamper‑evident seals on housings and conduct regular inspections to detect unauthorized access.
  • Enable authentication on any exposed debug interfaces so that only authorized service personnel can use them.
  • Follow the Johnson Controls Product Hardening Guide for additional hardening measures.

Generated by OpenCVE AI on August 28, 2026 at 07:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-732

Thu, 27 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description Debug and Test Interface With Improper Access Control vulnerability in Johnson Controls T2000 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects T2000: before 31.6.
Title T2000 open debug port
First Time appeared Johnson Controls
Johnson Controls t2000
CPEs cpe:2.3:a:johnson_controls:t2000:*:*:*:*:*:*:*:*
Vendors & Products Johnson Controls
Johnson Controls t2000
References
Metrics cvssV4_0

{'score': 5.2, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Johnson Controls T2000
cve-icon MITRE

Status: PUBLISHED

Assigner: jci

Published:

Updated: 2026-08-27T19:31:48.139Z

Reserved: 2026-07-20T19:51:19.089Z

Link: CVE-2026-64896

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-27T17:19:23.820

Modified: 2026-09-03T17:31:04.697

Link: CVE-2026-64896

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-01T14:23:11Z

Weaknesses
  • CWE-284

    Improper Access Control

  • CWE-732

    Incorrect Permission Assignment for Critical Resource