Massive Security Flaw in Johnson Controls’ iStar Pro: Door Controllers Wide Open to Hackers!

Warning: The iStar Pro Door Controller has a missing authentication vulnerability, making it susceptible to machine-in-the-middle attacks. With a CVSS v3 score of 9.1, it’s a critical issue. Consider using the physical dip switch on the GCM board to block ICU communications and mitigate this vulnerability.

Pro Dashboard

Hot Take:

Looks like Johnson Controls’ iStar Pro Door Controller has a security gap bigger than the Grand Canyon. The only thing missing here is a neon sign saying “Hackers Welcome!”

Key Points:

  • CVSS v3.1 score of 9.1, CVSS v4 score of 8.8
  • Vulnerability: Missing Authentication for Critical Function
  • Affected Products: Software House iStar Pro Door Controller and ICU
  • Risk: Allows for machine-in-the-middle attacks
  • Reported by: Reid Wightman of Dragos

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?