Johnson Controls Inc. TL280
Summary
A vulnerability in Johnson Controls Inc. TL280 devices, specifically versions prior to 5.63, allows attackers to access sensitive information due to the use of hardcoded credentials. CISA has identified this vulnerability as CVE-2026-27871.
IFF Assessment
The identified vulnerability in Johnson Controls TL280 devices, specifically the use of hardcoded credentials, allows for unauthorized access to sensitive information, posing a direct threat to defenders.
Severity
The CVSS score of 4.1 reflects a medium severity vulnerability that could allow an attacker to access sensitive information. The attack vector is likely network-based, and the impact is primarily information disclosure, with exploitability factors related to the 'Use of a Broken or Risky Cryptographic Algorithm' leading to hardcoded credentials.
Defender Context
Defenders should be aware of this vulnerability affecting Johnson Controls TL280 devices, particularly in critical infrastructure sectors. Implementing the suggested mitigations, such as restricting network access, monitoring logs, and rotating credentials, is crucial to prevent exploitation.