CVE-2026-64896
CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N
Summary
Debug and Test Interface With Improper Access Control vulnerability in Johnson Controls T2000 allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects T2000: before 31.6.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Johnson Controls | T2000 | 0 < 31.6 | affected |
Weaknesses
- Debug and Test Interface With Improper Access Control
Workarounds
If immediate update is not possible, Johnson Controls recommends the following mitigations:
Restrict physical access to the device by installing it in a secured equipment room that limits access to authorized service personnel only.
Implement tamper-evident seals on device housings and panel enclosures to detect and deter unauthorized physical access attempts.
Conduct periodic physical inspections of device installations to identify signs of tampering, unauthorized cable connections, or enclosure breaches.
Additional best-practice mitigations that end users can apply as a layer of defense:
Physically secure the device enclosure to prevent unauthorized access to internal circuit boards and ports.
Implement authentication mechanisms on any accessible debug interfaces to restrict access to authorized service personnel only.
Monitor physical access to device installations and implement tamper detection where possible.
Follow the recommendations in the Johnson Controls Product Hardening Guide available at https://www.johnsoncontrols.com/trust-center/cybersecurity/resources .
These mitigations reduce risk but may not fully remediate the vulnerability.
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.