Executive brief
Johnson Controls T2000 is a building automation and control system used to manage HVAC, fire suppression, and security systems in commercial facilities. A debug and test interface in T2000 lacks proper access controls, potentially allowing unauthorized users to bypass security restrictions and access functionality they should not be able to use, which could disrupt building operations or compromise system integrity.
Technical details
The vulnerability is a debug and test interface with improper access control (CWE-284) in Johnson Controls T2000 building automation system. The debug interface lacks proper authentication or authorization controls, allowing access to functionality that should be restricted by access control lists (ACLs). An attacker with network or local access to the T2000 system could potentially invoke debug or test functions without proper credentials, bypassing normal security constraints. The vulnerability affects versions before 31.6; patched versions are available in 31.6 and later.
Affected products
- Johnson Controls T2000 before 31.6
Timeline
- 2026-08-27: disclosed