Vulnerability Description
Use of a weak pseudo-random number generator, which may allow an attacker to read or inject encrypted PowerG packets.
Related Weaknesses (CWE)
References
- https://www.cisa.gov/news-events/ics-advisories/icsa-25-350-02
- https://www.johnsoncontrols.com/trust-center/cybersecurity/security-advisories
FAQ
What is CVE-2025-26379?
CVE-2025-26379 is a documented vulnerability. Use of a weak pseudo-random number generator, which may allow an attacker to read or inject encrypted PowerG packets.
How severe is CVE-2025-26379?
CVSS scoring is not yet available for CVE-2025-26379. Check NVD for updates.
Is there a patch for CVE-2025-26379?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.