Database/Control plane, storage & DevOps
Software House iSTAR Ultra, Ultra LT, Ultra G2 and Edge G2 door controllers: An unauthenticated user can log
Impact
An unauthenticated user can log into the controller with administrator rights. No exploitation, no chain - just log in as admin on the panel that governs the doors into the hall and the cages inside it. Administrator on an iSTAR panel means unlocking doors, enrolling credentials, changing door schedules, and editing or clearing the local event log so the entry leaves no record. Whoever walks in can pull drives containing model weights and customer data, attach a console to a running node, plug into the out-of-band management switch and reach every BMC in the row, or leave a hardware implant behind. For a bare-metal GPU provider this is a direct breach of the physical isolation guarantee sold to tenants, and because the log can be cleared from the same session, you may never be able to prove it did or did not happen. This is the fourth distinct critical or high finding on the iSTAR platform in this database's window, which is itself the finding: treat the platform as needing continuous advisory tracking rather than set-and-forget.
Who can reach it
Unauthenticated network access to the controller on the physical-security VLAN. Nothing else is required. That VLAN typically also carries CCTV, intercom and the security integrator's remote-support path, any of which is a route in from a wider network.
What to do
Firmware update per Johnson Controls' advisory for each affected iSTAR model - a security-integrator engagement with doors in local fallback during the flash, so it needs staff at affected doors for the window. Because the flaw grants administrator without authentication, assume any panel reachable during the exposure window may have had credentials added or the event log cleared: audit the panel's credential list and the head-end's cardholder database against a known-good baseline after patching. Structurally, put the physical-security VLAN behind a firewall with an explicit allow-list from the head-end only, and stop treating that VLAN as trusted because it is 'the security network'.
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.