CVE-2023-3127: Johnsoncontrols Edge g2 Firmware

Critical severity, CVSS 9.8. EPSS: 0.6% chance of exploitation in the next 30 days.

An unauthenticated user could log into iSTAR Ultra, iSTAR Ultra LT, iSTAR Ultra G2, and iSTAR Edge G2 with administrator rights.

Affected products

  • Johnsoncontrols Edge g2 Firmware: before 6.9.2 (fixed in 6.9.2); version 6.9.2 only
  • Johnsoncontrols Istar Ultra Firmware: from 6.8.6, before 6.9.2 (fixed in 6.9.2); version 6.9.2 only
  • Johnsoncontrols Istar Ultra g2 Firmware: before 6.9.2 (fixed in 6.9.2); version 6.9.2 only
  • Johnsoncontrols Istar Ultra Lt Firmware: from 6.8.6, before 6.9.2 (fixed in 6.9.2); version 6.9.2 only

Published 2023-07-11. Last modified 2026-06-17.