Debug and Test Interface With Improper Access Control vulnerability in Johnson Controls T2000 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects T2000: before 31.6.
History

Thu, 27 Aug 2026 18:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-732

Thu, 27 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description Debug and Test Interface With Improper Access Control vulnerability in Johnson Controls T2000 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects T2000: before 31.6.
Title T2000 open debug port
First Time appeared Johnson Controls
Johnson Controls t2000
CPEs cpe:2.3:a:johnson_controls:t2000:*:*:*:*:*:*:*:*
Vendors & Products Johnson Controls
Johnson Controls t2000
References
Metrics cvssV4_0

{'score': 5.2, 'vector': 'CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: jci

Published: 2026-08-27T14:42:33.253Z

Updated: 2026-08-27T19:31:48.139Z

Reserved: 2026-07-20T19:51:19.089Z

Link: CVE-2026-64896

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-27T17:19:23.820

Modified: 2026-08-27T20:18:20.347

Link: CVE-2026-64896

cve-icon Redhat

No data.