Critical Johnson Controls Products Vulnerabilities Enables Remote SQL Injection Attacks
A critical advisory addressing a severe SQL injection vulnerability affecting multiple Johnson Controls industrial control system products. The vulnerability, tracked as CVE-2025-26385, carries a maximum CVSS v3 severity score of 10.0,…
A critical advisory addressing a severe SQL injection vulnerability affecting multiple Johnson Controls industrial control system products. The vulnerability, tracked as CVE-2025-26385, carries a maximum CVSS v3 severity score of 10.0, indicating the highest level of risk to affected infrastructure. The flaw stems from improper neutralization of special elements used in command injection, allowing remote […]
(http.request.uri.path contains "CVE-2025-26385" or http.request.body.mime contains "exploit" or cf.threat_score gt 20)
Operative Incident Triage Checklist
Geführter 5-Stufen Runbook-Ablauf für Metasys (Extended Application and Data Server (ADX) installed with SQL Express deployed as part of the Metasys 14.1 installation) + 4 weitere
0/5 erledigt
NIS2 Meldefrist: 48 Stunden (EU NIS2)Status lokal gespeichert
CLI One-Liners
Mobile Terminal Incident Commands
1-Tap SSH Clipboard
FIREWALL / INGRESS
Linux Ingress Emergency Isolation (nftables)
Blockiert sofort unberechtigte Neuverbindungen auf exponierten Standard-Ports.
sudo nft add rule inet filter input ct state new tcp dport { 80, 443, 8080, 8443, 3000 } drop comment "EMERGENCY_QUARANTINE_CVE-2025-26385"
Sofortige Wirkung im Linux-Kernel. SSH (Port 22) bleibt unberührt.
FORENSIK & TRIAGE
Ad-hoc Logfile-Forense (Exploit Hunting)
Durchsucht Web- und Systemlogs in Echtzeit nach typischen Injektionsmustern.
🏢 Vendor: Johnson Controls(1 Produkt(e), 5 Version(en))
📦 MetasysL2 — Application Runtime / Module
Betroffene Versionen: Extended Application and Data Server (ADX) installed with SQL Express deployed as part of the Metasys 14.1 installation, LCS8500 or NAE8500 installed with SQL Express deployed as part of the Metasys installation Releases 12.0 through 14.1, Controller Configuration Tool (CCT) installed with SQL Express deployed as part of the CCT installation 17.0 and prior, Application and Data Server (ADS) installed with SQL Express deployed as part of the Metasys 14.1 and prior installation, System Configuration Tool (SCT) installed with SQL Express deployed as part of the SCT installation 17.1 and prior
Verschlüsselung im Ruhezustand & Unveränderbare SIEM-Logs
Geschützt (KMS Envelope Encryption)
Angreifer penetrieren Perimeter und WAF ungehindert. Schicht 3 (Micro-Segmentierung & Port-Drop) bildet die entscheidende Stop-Linie zur Schadenseindämmung.
3. Compliance, SLA & Vendor Adherence
⏱️
EU NIS2 / ISO 27001 Remediation SLA Tracker CVE-2025-26385
Erhöhte Gefahr der Ausnutzung. Vorrangige Intervention, WAF-Virtual-Patching und Ingress-Filterung binnen 24h.
NIS-2 / KRITIS Frühwarn- und Meldepflicht (24h-Frist gem. § 30 BSIG-E / EU-Richtlinie 2022/2555). Bei personenbezogenen Daten droht DSGVO-Haftung bis zu 10 Mio. € bzw. 2% des weltweiten Jahresumsatzes.
Advisory Radar
Hersteller-Sicherheitsmeldungen & Patch-Status
Workaround & Virtual-Patching empfohlen
Handlungsempfehlung für Administratoren
Öffentliche PoCs existieren. Isolieren Sie das System oder wenden Sie Micro-Segmentierungsregeln an, bis offizielle Patches vorliegen.
Analyse für CVE-2025-26385 auf Basis von Live-CTI (ENISA EUVD): CVSS 0.0 · EPSS 0.0% · CISA KEV: nein. Handlungsableitung aus den verlinkten Hersteller-Quellen.
🛡️ Angriffsfläche & Exposure
Netzwerk/Remote-Zugriff ohne Vorauthentifizierung möglich.
⚡ Empfohlene Sofortmaßnahmen
1. Perimeter-Inspektion: Relevante Portfreigaben und exponierte Endpunkte unverzüglich scannen.
2. Patch-Applikation: Hersteller-Hotfix einspielen oder betroffene Daemons in isolierte DMZ-Segmente überführen.
3. Telemetrie & EDR-Alerts: Prozessaufrufe und Child-Processes auf anomale Shell-Spawns überwachen.
🔗 Verwandte Schwachstellen (gleicher Hersteller)
CVE-2023-4804CVE-2023-4804 | An unauthorized user could access debug features in Quantum HD Unity products that were accidentally exposed.
CVSS 10.0
CVE-2023-2024CVE-2023-2024 | Improper authentication in OpenBlue Enterprise Manager Data Collector versions prior to 3.2.5.75 allow access to an unauthorized user under certain circumstances.
CVSS 10.0
CVE-2021-36206CVE-2021-36206 | All versions of CEVAS prior to 1.01.46 do not sufficiently validate user-controllable input and could allow a user to bypass authentication and retrieve data with specially crafted SQL queries.
CVSS 10.0
Synthetische RAG-Antwort
HAND-OFF
Auf Smartphone übergeben (CVE-2025-26385)
Scannen Sie den QR-Code mit der Smartphone-Kamera für sofortigen mobilen Zugriff: