top of page
perceptive_background_267k.jpg

Johnson Controls OpenBlue Mobile Web Application for OpenBlue Workplace

Published:

4 december 2025 om 12:00:00

Alert date:

5 december 2025 om 08:03:23

Source:

cisa.gov

Click to open the original link from this advisory

Johnson Controls OpenBlue Mobile Web Application for OpenBlue Workplace versions 2025.1.2 and prior contain a Direct Request ('Forced Browsing') vulnerability (CVE-2025-26381) with CVSS v3.1 score of 9.3. The vulnerability allows attackers to gain unauthorized access to sensitive information through remote exploitation with low attack complexity. Affects critical infrastructure sectors including commercial facilities, manufacturing, energy, government services, and transportation systems worldwide. Mitigation requires upgrading to patch level 2025.1.3 or disabling the mobile application in Microsoft IIS.

Technical details

Mitigation steps:

Affected products:

Johnson Controls OpenBlue Mobile Web Application for OpenBlue Workplace

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page