On-Chip Debug Interface Issue in Neo Series MVP2 by Johnson Controls
CVE-2026-34494

7.2HIGH

Key Information:

Vendor
CVE Published:
1 October 2026

What is CVE-2026-34494?

The On-Chip Debug Interface vulnerability in the Neo Series MVP2 by Johnson Controls could potentially allow unauthorized data collection from common resource locations. This affects devices running versions prior to 3.3b63, posing security risks if the devices are not updated. It is crucial for users to review their systems and apply recommended security patches to mitigate exposure.

Affected Version(s)

Neo Series MVP2 0 < 3.3b63

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.