{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-64896","assignerOrgId":"7281d04a-a537-43df-bfb4-fa4110af9d01","state":"PUBLISHED","assignerShortName":"jci","dateReserved":"2026-07-20T19:51:19.089Z","datePublished":"2026-08-27T14:42:33.253Z","dateUpdated":"2026-08-27T19:31:48.139Z"},"containers":{"cna":{"providerMetadata":{"orgId":"7281d04a-a537-43df-bfb4-fa4110af9d01","shortName":"jci","dateUpdated":"2026-08-27T14:42:33.253Z"},"title":"T2000 open debug port","datePublic":"2026-08-25T14:32:00.000Z","problemTypes":[{"descriptions":[{"lang":"en","description":"Debug and Test Interface With Improper Access Control"}]}],"impacts":[{"descriptions":[{"lang":"en","value":"Accessing Functionality Not Properly Constrained by ACLs"}]}],"affected":[{"vendor":"Johnson Controls","product":"T2000","versions":[{"status":"affected","version":"0","lessThan":"31.6","versionType":"custom"}],"defaultStatus":"unaffected"}],"cpeApplicability":[{"operator":"OR","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:johnson_controls:t2000:*:*:*:*:*:*:*:*","versionStartIncluding":"0","versionEndExcluding":"31.6"}]}]}],"descriptions":[{"lang":"en","value":"Debug and Test Interface With Improper Access Control vulnerability in Johnson Controls T2000 allows Accessing Functionality Not Properly Constrained by ACLs.\n\nThis issue affects T2000: before 31.6.","supportingMedia":[{"type":"text/html","base64":false,"value":"Debug and Test Interface With Improper Access Control vulnerability in Johnson Controls T2000 allows Accessing Functionality Not Properly Constrained by ACLs.<p>This issue affects T2000: before 31.6.</p>"}]}],"references":[{"url":"https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories"}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"PHYSICAL","attackComplexity":"LOW","attackRequirements":"NONE","privilegesRequired":"NONE","userInteraction":"NONE","vulnConfidentialityImpact":"NONE","subConfidentialityImpact":"NONE","vulnIntegrityImpact":"LOW","subIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subAvailabilityImpact":"NONE","exploitMaturity":"NOT_DEFINED","Safety":"NOT_DEFINED","Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","valueDensity":"NOT_DEFINED","vulnerabilityResponseEffort":"NOT_DEFINED","providerUrgency":"NOT_DEFINED","version":"4.0","baseSeverity":"MEDIUM","baseScore":5.2,"vectorString":"CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:H/SC:N/SI:N/SA:N"}}],"workarounds":[{"lang":"en","value":"If immediate update is not possible, Johnson Controls recommends the following mitigations: \n\n\n\n  *  \n\nRestrict physical access to the device by installing it in a secured equipment room that limits access to authorized service personnel only. \n\n\n\n\n\n\n  *  \n\nImplement tamper-evident seals on device housings and panel enclosures to detect and deter unauthorized physical access attempts. \n\n\n\n\n\n\n  *  \n\nConduct periodic physical inspections of device installations to identify signs of tampering, unauthorized cable connections, or enclosure breaches. \n\n\n\n\n\n\n\n\nAdditional best-practice mitigations that end users can apply as a layer of defense: \n\n\n\n  *  \n\nPhysically secure the device enclosure to prevent unauthorized access to internal circuit boards and ports. \n\n\n\n\n\n\n  *  \n\nImplement authentication mechanisms on any accessible debug interfaces to restrict access to authorized service personnel only. \n\n\n\n\n\n\n  *  \n\nMonitor physical access to device installations and implement tamper detection where possible. \n\n\n\n\n\n\n  *  \n\nFollow the recommendations in the Johnson Controls Product Hardening Guide available at  https://www.johnsoncontrols.com/trust-center/cybersecurity/resources . \n\n\n\n\n\n\n\n\nThese mitigations reduce risk but may not fully remediate the vulnerability.","supportingMedia":[{"type":"text/html","base64":false,"value":"<div><p>If immediate update is not possible, Johnson Controls recommends the following mitigations:&nbsp;</p></div><div><ul><li><p>Restrict physical access to the device by installing it in a secured equipment room that limits access to authorized service personnel only.&nbsp;</p></li></ul></div><div><ul><li><p>Implement tamper-evident seals on device housings and panel enclosures to detect and deter unauthorized physical access attempts.&nbsp;</p></li></ul></div><div><ul><li><p>Conduct periodic physical inspections of device installations to identify signs of tampering, unauthorized cable connections, or enclosure breaches.&nbsp;</p></li></ul></div><div><p>Additional best-practice mitigations that end users can apply as a layer of defense:&nbsp;</p></div><div><ul><li><p>Physically secure&nbsp;the device&nbsp;enclosure to prevent unauthorized access to internal circuit boards and ports.&nbsp;</p></li></ul></div><div><ul><li><p>Implement authentication mechanisms on any accessible debug interfaces to restrict access to authorized service personnel only.&nbsp;</p></li></ul></div><div><ul><li><p>Monitor physical access to device installations and implement tamper detection where possible.&nbsp;</p></li></ul></div><div><ul><li><p>Follow the recommendations in the Johnson Controls Product Hardening Guide available at&nbsp;<a href=\"https://www.johnsoncontrols.com/trust-center/cybersecurity/resources\" target=\"_blank\" rel=\"noreferrer noopener\">https://www.johnsoncontrols.com/trust-center/cybersecurity/resources</a>.&nbsp;</p></li></ul></div><div><p>These mitigations reduce risk but may not fully remediate the vulnerability.&nbsp;&nbsp;</p></div>"}]}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.5"}},"adp":[{"problemTypes":[{"descriptions":[{"type":"CWE","cweId":"CWE-284","lang":"en","description":"CWE-284 Improper Access Control"},{"type":"CWE","cweId":"CWE-732","lang":"en","description":"CWE-732 Incorrect Permission Assignment for Critical Resource"}]}],"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-08-27T19:31:28.626751Z","id":"CVE-2026-64896","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-08-27T19:31:48.139Z"}}]}}