CVE-2025-61736 describes a vulnerability where a product fails to re-establish communication after a certificate expires. While no specific affected products are listed, this issue is categorized as a CWE-298 (Improper Handling of Inconsistent Structures). Rated with a CVSS v4.0 score of 7.1 (High), this vulnerability has an adjacent attack vector and low attack complexity, requiring no user interaction or privileges. Successful exploitation could lead to high availability impact, as the product would cease functioning correctly. Currently, there is no evidence of active exploitation, nor are there any publicly available exploit codes in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, indicating low public awareness at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Johnson Controls | ISTAReX, ISTAR Edge, ISTAR Ultra LT, ISTAR Ultra , ISTAR Ultra SE | iSTAR All versions prior to TLS 1.2CNA affecteddefault affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.4 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.