{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2025-26379",
        "assignerOrgId": "7281d04a-a537-43df-bfb4-fa4110af9d01",
        "state": "PUBLISHED",
        "assignerShortName": "jci",
        "dateReserved": "2025-02-07T14:15:53.879Z",
        "datePublished": "2025-12-22T14:21:29.597Z",
        "dateUpdated": "2025-12-22T16:19:25.130Z"
    },
    "containers": {
        "cna": {
            "affected": [
                {
                    "defaultStatus": "unaffected",
                    "product": "IQ Panels2, 2+, IQHub, IQPanel 4, PowerG",
                    "vendor": "Johnson Controls",
                    "versions": [
                        {
                            "lessThanOrEqual": "2",
                            "status": "affected",
                            "version": "IQ Panels2",
                            "versionType": "custom"
                        },
                        {
                            "lessThanOrEqual": "2+",
                            "status": "affected",
                            "version": "IQ Panel 2+",
                            "versionType": "custom"
                        },
                        {
                            "status": "affected",
                            "version": "IQHub",
                            "versionType": "custom"
                        },
                        {
                            "lessThanOrEqual": "4.6.0",
                            "status": "affected",
                            "version": "IQPanel 4",
                            "versionType": "custom"
                        },
                        {
                            "lessThanOrEqual": "53.02",
                            "status": "affected",
                            "version": "PowerG",
                            "versionType": "custom"
                        }
                    ]
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "James Chambersof NCC Group"
                },
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "and Sultan Qasim Khan NCC Group"
                }
            ],
            "datePublic": "2025-12-16T14:11:00.000Z",
            "descriptions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "Use of a weak pseudo-random number generator, which may allow an attacker to read or inject encrypted PowerG packets.<br>"
                        }
                    ],
                    "value": "Use of a weak pseudo-random number generator, which may allow an attacker to read or inject encrypted PowerG packets."
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-59",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-59 Session Credential Falsification through Prediction"
                        }
                    ]
                }
            ],
            "metrics": [
                {
                    "cvssV4_0": {
                        "Automatable": "NOT_DEFINED",
                        "Recovery": "NOT_DEFINED",
                        "Safety": "NOT_DEFINED",
                        "attackComplexity": "LOW",
                        "attackRequirements": "NONE",
                        "attackVector": "ADJACENT",
                        "baseScore": 7.2,
                        "baseSeverity": "HIGH",
                        "exploitMaturity": "NOT_DEFINED",
                        "privilegesRequired": "NONE",
                        "providerUrgency": "NOT_DEFINED",
                        "subAvailabilityImpact": "NONE",
                        "subConfidentialityImpact": "LOW",
                        "subIntegrityImpact": "LOW",
                        "userInteraction": "NONE",
                        "valueDensity": "NOT_DEFINED",
                        "vectorString": "CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:L/SC:L/SI:L/SA:N",
                        "version": "4.0",
                        "vulnAvailabilityImpact": "LOW",
                        "vulnConfidentialityImpact": "LOW",
                        "vulnIntegrityImpact": "HIGH",
                        "vulnerabilityResponseEffort": "NOT_DEFINED"
                    },
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ]
                }
            ],
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "cweId": "CWE-338",
                            "description": "CWE-338 Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG)",
                            "lang": "en",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "providerMetadata": {
                "orgId": "7281d04a-a537-43df-bfb4-fa4110af9d01",
                "shortName": "jci",
                "dateUpdated": "2025-12-22T14:21:29.597Z"
            },
            "references": [
                {
                    "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories"
                },
                {
                    "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-350-02"
                }
            ],
            "solutions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "a.  Update IQ Panel 4’s to version 4.6.1/4.6.1i<br>b.  Devices that support PowerG+ should use PowerG v53.05 or later. <br>c.  During the installation or enrollment of PowerG+ devices, enter the PIN code in the PIN Code field on the sensor enrollment screen. For additional security, Johnson Controls recommends only authorized company personnel or integrators be present during the pairing process<br>d.  Replace all End-of-Life Products (IQ Panel 2, IQ Panel 2+, IQ Hub) with the latest IQ Panel 4 using firmware version 4.6.1 or greater<br><br>"
                        }
                    ],
                    "value": "a.  Update IQ Panel 4’s to version 4.6.1/4.6.1i\nb.  Devices that support PowerG+ should use PowerG v53.05 or later. \nc.  During the installation or enrollment of PowerG+ devices, enter the PIN code in the PIN Code field on the sensor enrollment screen. For additional security, Johnson Controls recommends only authorized company personnel or integrators be present during the pairing process\nd.  Replace all End-of-Life Products (IQ Panel 2, IQ Panel 2+, IQ Hub) with the latest IQ Panel 4 using firmware version 4.6.1 or greater"
                }
            ],
            "source": {
                "discovery": "UNKNOWN"
            },
            "title": "Johnson Controls IQ Panels2, 2+, IQHub, IQPanel 4, PowerG use of Cryptographically Weak Pseudo-Random Number Generator",
            "x_generator": {
                "engine": "Vulnogram 0.5.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2025-12-22T16:19:13.074335Z",
                                "id": "CVE-2025-26379",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2025-12-22T16:19:25.130Z"
                }
            }
        ]
    }
}