Massive Security Flaw in Johnson Controls’ iStar Pro: Door Controllers Wide Open to Hackers!

Warning: The iStar Pro Door Controller has a missing authentication vulnerability, making it susceptible to machine-in-the-middle attacks. With a CVSS v3 score of 9.1, it’s a critical issue. Consider using the physical dip switch on the GCM board to block ICU communications and mitigate this…

Hot Take:

Looks like Johnson Controls’ iStar Pro Door Controller has a security gap bigger than the Grand Canyon. The only thing missing here is a neon sign saying “Hackers Welcome!”

Key Points:

  • CVSS v3.1 score of 9.1, CVSS v4 score of 8.8
  • Vulnerability: Missing Authentication for Critical Function
  • Affected Products: Software House iStar Pro Door Controller and ICU
  • Risk: Allows for machine-in-the-middle attacks
  • Reported by: Reid Wightman of Dragos

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here