CVE-2025-26383
CVE-2025-26383
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.3EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
11 Jun 2025Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The iSTAR Configuration Utility (ICU) tool leaks memory, which could result in the unintended exposure of unauthorized data from the Windows PC that ICU is running on.
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:L/VI:N/VA:N/SC:H/SI:N/SA:N
Affected products
Johnson Controls · iSTAR Configuration Utility (ICU)Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →