The Containment Era is here. →Explore

Executive Summary

In December 2025, Johnson Controls publicly disclosed critical vulnerabilities (CVE-2025-43873 and CVE-2025-43874) affecting several versions of its iSTAR Ultra and Edge G2 door controllers used in building automation across critical infrastructure sectors worldwide. These OS Command Injection flaws, exploitable remotely with low attack complexity and minimal user interaction, could allow attackers to gain full control of vulnerable devices, modify firmware, and potentially disrupt or compromise secure building environments. The vulnerabilities were responsibly reported by Reid Wightman of Dragos, and patches have been made available for affected products.

This incident highlights increasing threats targeting operational technology (OT) in critical sectors, as cybercriminals and nation-state actors leverage software supply chain and device-level weaknesses for initial access. The prevalence of command injection vulnerabilities, coupled with rising demands for segmentation and zero trust architectures, elevates the urgency for organizations to update OT and IoT assets and enforce proactive defense strategies.

Why This Matters Now

Industrial control devices are increasingly targeted by sophisticated attackers aiming to exploit unpatched vulnerabilities with high business impact. The Johnson Controls incident underscores the importance of urgently patching connected OT systems, segmenting networks, and enforcing secure remote access, especially as regulatory scrutiny mounts and attackers exploit simple yet devastating vulnerabilities across critical infrastructure.

Attack Path Analysis

Related CVEs

MITRE ATT&CK® Techniques

Potential Compliance Exposure

Sector Implications

Sources

Frequently Asked Questions

The incident revealed issues with secure network segmentation, lack of encryption for device traffic, and insufficient intrusion prevention—gaps addressed in NIST 800-53, PCI DSS, and HIPAA for OT systems.

Cloud Native Security Fabric Mitigations and ControlsCNSF

Zero Trust segmentation, east-west isolation, and real-time network enforcement would have significantly constrained each attack phase: limiting initial exposure, blocking lateral movement, identifying anomalous behavior, and preventing unauthorized outbound data flows.

Initial Compromise

Control: Cloud Firewall (ACF)

Mitigation: Direct external-to-device exploits would be blocked by strict perimeter controls.

Privilege Escalation

Control: Threat Detection & Anomaly Response

Mitigation: Unusual privilege escalation actions are rapidly identified for incident response.

Lateral Movement

Control: Zero Trust Segmentation

Mitigation: Host-to-host movement is restricted by least privilege networking policies.

Command & Control

Control: Inline IPS (Suricata)

Mitigation: Known C2 and exploit patterns are detected and disrupted in real time.

Exfiltration

Control: Egress Security & Policy Enforcement

Mitigation: Unapproved outbound data flows are blocked or flagged.

Impact (Mitigations)

Rapid detection and response to destructive or unauthorized device changes.

Impact at a Glance

Affected Business Functions

  • Physical Security
  • Access Control Systems
Operational Disruption

Estimated downtime: 3 days

Financial Impact

Estimated loss: $50,000

Data Exposure

Potential exposure of sensitive access control configurations and logs.

Recommended Actions

  • Enforce strict perimeter firewall and segmentation for all control system devices to block unauthorized external access.
  • Deploy zero trust segmentation and least privilege policies to prevent lateral movement between workloads and ICS assets.
  • Enable inline threat detection and anomaly response to detect privilege escalation and command injection activity early.
  • Apply strict egress filtering to block unauthorized outbound connections and data exfiltration attempts.
  • Increase centralized multicloud visibility and real-time monitoring of ICS network traffic and controller behavior.

Secure the Paths Between Cloud Workloads

A cloud-native security fabric that enforces Zero Trust across workload communication—reducing attack paths, compliance risk, and operational complexity.

Cta pattren Image