Johnson Controls OpenBlue Employee
Summary
Several vulnerabilities have been identified in Johnson Controls OpenBlue Employee software, versions up to and including V2025.3.1. Successful exploitation could allow attackers to upload malicious files, execute stored cross-site scripting (XSS) attacks, or inject arbitrary HTML content. Johnson Controls recommends applying the latest product updates to mitigate these risks.
IFF Assessment
The identified vulnerabilities allow attackers to upload malicious files, execute XSS, and inject HTML, posing a significant risk to system security.
Severity
The CVSS score of 2.4 reflects a low severity rating primarily due to the 'Unrestricted Upload of File with Dangerous Type' vulnerability, which is a component of the overall risk. The article also mentions other vulnerabilities like XSS, which could have higher individual scores, but the presented aggregate score is low.
Defender Context
This alert highlights critical vulnerabilities in industrial control systems software used globally. Defenders should prioritize patching affected Johnson Controls OpenBlue Employee systems and consider network segmentation and strict access controls to limit potential lateral movement if exploitation occurs. Monitoring for unauthorized file uploads and unexpected HTML content within the application should also be a focus.