CVE-2026-64896

Summary

Debug and Test Interface With Improper Access Control vulnerability in Johnson Controls T2000 allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects T2000: before 31.6.

Affected Software

VendorProductVersion RangeStatus
Johnson ControlsT20000 < 31.6affected

Weaknesses

  • Debug and Test Interface With Improper Access Control

Workarounds

If immediate update is not possible, Johnson Controls recommends the following mitigations: 

Restrict physical access to the device by installing it in a secured equipment room that limits access to authorized service personnel only. 

Implement tamper-evident seals on device housings and panel enclosures to detect and deter unauthorized physical access attempts. 

Conduct periodic physical inspections of device installations to identify signs of tampering, unauthorized cable connections, or enclosure breaches. 

Additional best-practice mitigations that end users can apply as a layer of defense: 

Physically secure the device enclosure to prevent unauthorized access to internal circuit boards and ports. 

Implement authentication mechanisms on any accessible debug interfaces to restrict access to authorized service personnel only. 

Monitor physical access to device installations and implement tamper detection where possible. 

Follow the recommendations in the Johnson Controls Product Hardening Guide available at  https://www.johnsoncontrols.com/trust-center/cybersecurity/resources

These mitigations reduce risk but may not fully remediate the vulnerability.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References