Debug and Test Interface With Improper Access Control vulnerability in Johnson Controls T2000 allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects T2000: before 31.6.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

If immediate update is not possible, Johnson Controls recommends the following mitigations:  * Restrict physical access to the device by installing it in a secured equipment room that limits access to authorized service personnel only.  * Implement tamper-evident seals on device housings and panel enclosures to detect and deter unauthorized physical access attempts.  * Conduct periodic physical inspections of device installations to identify signs of tampering, unauthorized cable connections, or enclosure breaches.  Additional best-practice mitigations that end users can apply as a layer of defense:  * Physically secure the device enclosure to prevent unauthorized access to internal circuit boards and ports.  * Implement authentication mechanisms on any accessible debug interfaces to restrict access to authorized service personnel only.  * Monitor physical access to device installations and implement tamper detection where possible.  * Follow the recommendations in the Johnson Controls Product Hardening Guide available at  https://www.johnsoncontrols.com/trust-center/cybersecurity/resources .  These mitigations reduce risk but may not fully remediate the vulnerability.

History

Thu, 27 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description Debug and Test Interface With Improper Access Control vulnerability in Johnson Controls T2000 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects T2000: before 31.6.
Title T2000 open debug port
First Time appeared Johnson Controls
Johnson Controls t2000
CPEs cpe:2.3:a:johnson_controls:t2000:*:*:*:*:*:*:*:*
Vendors & Products Johnson Controls
Johnson Controls t2000
References
Metrics cvssV4_0

{'score': 5.2, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: jci

Published:

Updated: 2026-08-27T14:42:33.253Z

Reserved: 2026-07-20T19:51:19.089Z

Link: CVE-2026-64896

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses

No weakness.