{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2025-61738",
        "assignerOrgId": "7281d04a-a537-43df-bfb4-fa4110af9d01",
        "state": "PUBLISHED",
        "assignerShortName": "jci",
        "dateReserved": "2025-09-30T15:51:17.096Z",
        "datePublished": "2025-12-22T10:07:19.789Z",
        "dateUpdated": "2025-12-22T14:09:49.340Z"
    },
    "containers": {
        "cna": {
            "affected": [
                {
                    "defaultStatus": "unaffected",
                    "product": "IQPanel2,\tIQHub,IQPanel2+,IQPanel 4,PowerG",
                    "vendor": "Johnson Controls",
                    "versions": [
                        {
                            "lessThanOrEqual": "2",
                            "status": "affected",
                            "version": "IQPanel2",
                            "versionType": "custom"
                        },
                        {
                            "status": "affected",
                            "version": "IQHub",
                            "versionType": "custom"
                        },
                        {
                            "lessThanOrEqual": "2+",
                            "status": "affected",
                            "version": "IQPanel2+",
                            "versionType": "custom"
                        },
                        {
                            "lessThanOrEqual": "4.6.0",
                            "status": "affected",
                            "version": ",IQPanel 4",
                            "versionType": "custom"
                        },
                        {
                            "lessThanOrEqual": "53.02",
                            "status": "affected",
                            "version": "PowerG",
                            "versionType": "custom"
                        }
                    ]
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "James Chambers of NCC Group"
                },
                {
                    "lang": "en",
                    "type": "finder",
                    "value": "Sultan Qasim Khan of NCC Group"
                }
            ],
            "datePublic": "2025-12-16T09:40:00.000Z",
            "descriptions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "&nbsp;Under certain circumstances, attacker can capture the network key, read or write encrypted packets on the PowerG network."
                        }
                    ],
                    "value": "Under certain circumstances, attacker can capture the network key, read or write encrypted packets on the PowerG network."
                }
            ],
            "impacts": [
                {
                    "capecId": "CAPEC-158",
                    "descriptions": [
                        {
                            "lang": "en",
                            "value": "CAPEC-158 Sniffing Network Traffic"
                        }
                    ]
                }
            ],
            "metrics": [
                {
                    "cvssV4_0": {
                        "Automatable": "NOT_DEFINED",
                        "Recovery": "NOT_DEFINED",
                        "Safety": "NOT_DEFINED",
                        "attackComplexity": "HIGH",
                        "attackRequirements": "NONE",
                        "attackVector": "NETWORK",
                        "baseScore": 2.3,
                        "baseSeverity": "LOW",
                        "exploitMaturity": "NOT_DEFINED",
                        "privilegesRequired": "NONE",
                        "providerUrgency": "NOT_DEFINED",
                        "subAvailabilityImpact": "NONE",
                        "subConfidentialityImpact": "NONE",
                        "subIntegrityImpact": "NONE",
                        "userInteraction": "PASSIVE",
                        "valueDensity": "NOT_DEFINED",
                        "vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N",
                        "version": "4.0",
                        "vulnAvailabilityImpact": "NONE",
                        "vulnConfidentialityImpact": "LOW",
                        "vulnIntegrityImpact": "NONE",
                        "vulnerabilityResponseEffort": "NOT_DEFINED"
                    },
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ]
                }
            ],
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "cweId": "CWE-319",
                            "description": "CWE-319 Cleartext Transmission of Sensitive Information",
                            "lang": "en",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "providerMetadata": {
                "orgId": "7281d04a-a537-43df-bfb4-fa4110af9d01",
                "shortName": "jci",
                "dateUpdated": "2025-12-22T14:09:49.340Z"
            },
            "references": [
                {
                    "url": "https://www.cisa.gov/news-events/ics-advisories/icsa-25-350-02"
                },
                {
                    "url": "https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories"
                }
            ],
            "solutions": [
                {
                    "lang": "en",
                    "supportingMedia": [
                        {
                            "base64": false,
                            "type": "text/html",
                            "value": "a.  Update IQ Panel 4’s to version 4.6.1/4.6.1i<br>b.  Devices that support PowerG+ should use PowerG v53.05 or later. <br>c.  During the installation or enrollment of PowerG+ devices, enter the PIN code in the PIN Code field on the sensor enrollment screen. For additional security, Johnson Controls recommends only authorized company personnel or integrators be present during the pairing process<br>d.  Replace all End-of-Life Products (IQ Panel 2, IQ Panel 2+, IQ Hub) with the latest IQ Panel 4 using firmware version 4.6.1 or greater<br><br>"
                        }
                    ],
                    "value": "a.  Update IQ Panel 4’s to version 4.6.1/4.6.1i\nb.  Devices that support PowerG+ should use PowerG v53.05 or later. \nc.  During the installation or enrollment of PowerG+ devices, enter the PIN code in the PIN Code field on the sensor enrollment screen. For additional security, Johnson Controls recommends only authorized company personnel or integrators be present during the pairing process\nd.  Replace all End-of-Life Products (IQ Panel 2, IQ Panel 2+, IQ Hub) with the latest IQ Panel 4 using firmware version 4.6.1 or greater"
                }
            ],
            "source": {
                "discovery": "UNKNOWN"
            },
            "title": "Johnson Controls PowerG and IQPanel cleartext transmission of sensitive information",
            "x_generator": {
                "engine": "Vulnogram 0.5.0"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2025-12-22T13:14:58.080040Z",
                                "id": "CVE-2025-61738",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2025-12-22T13:18:28.352Z"
                }
            }
        ]
    }
}