Johnson Controls iSTAR Configuration Utility (ICU) has Stack-based Buffer Overflow vulnerability. This issue affects iSTAR Configuration Utility (ICU) version 6.9.7 and prior. Successful exploitation of this vulnerability could result in failure within the operating system of the machine hosting the ICU tool.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
Update the ICU to version 6.9.8
Workaround
No workaround given by the vendor.
References
History
Wed, 28 Jan 2026 20:45:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stack-based Buffer Overflow vulnerability in Johnson Controls iSTAR Configuration Utility (ICU) allows Overflow Buffers.This issue affects iSTAR Configuration Utility (ICU): iSTAR Configuration Utility (ICU) tool version 6.9.7 and prior. | Johnson Controls iSTAR Configuration Utility (ICU) has Stack-based Buffer Overflow vulnerability. This issue affects iSTAR Configuration Utility (ICU) version 6.9.7 and prior. Successful exploitation of this vulnerability could result in failure within the operating system of the machine hosting the ICU tool. |
| Title | Johnson Controls iSTAR Configuration Utility (ICU) tool has Stack-based Buffer Overflow | Stack-based Buffer Overflow in Johnson Controls iSTAR Configuration Utility (ICU) tool |
Wed, 28 Jan 2026 20:30:00 +0900
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stack-based Buffer Overflow vulnerability in Johnson Controls iSTAR Configuration Utility (ICU) allows Overflow Buffers.This issue affects iSTAR Configuration Utility (ICU): iSTAR Configuration Utility (ICU) tool version 6.9.7 and prior. | |
| Title | Johnson Controls iSTAR Configuration Utility (ICU) tool has Stack-based Buffer Overflow | |
| Weaknesses | CWE-121 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: jci
Published:
Updated: 2026-01-28T15:49:08.575Z
Reserved: 2025-02-07T14:15:53.880Z
Link: CVE-2025-26386
No data.
Status : Received
Published: 2026-01-28T12:15:50.370
Modified: 2026-01-28T12:15:50.370
Link: CVE-2025-26386
No data.
OpenCVE Enrichment
No data.
Weaknesses