Johnson Controls Inc. Airwall
Summary
Multiple vulnerabilities have been identified in Johnson Controls Inc. Airwall versions prior to 4.0.4. Successful exploitation could allow an attacker to decrypt sensitive data, bypass authentication, or gain unauthorized access to system resources. The vulnerabilities include the use of a hard-coded cryptographic key and external control of file names or paths.
IFF Assessment
The identified vulnerabilities allow attackers to decrypt sensitive data, bypass authentication, and gain unauthorized access, posing a significant risk to system security.
Severity
The CVSS score of 6.8 reflects a high severity due to vulnerabilities like hard-coded cryptographic keys which facilitate data decryption and authentication bypass, alongside the risk of unauthorized access to system resources.
Defender Context
Defenders should prioritize patching or mitigating these vulnerabilities in Johnson Controls Inc. Airwall devices. The presence of hard-coded keys is a critical issue that attackers can exploit for widespread compromise. Monitoring for unauthorized access attempts and unusual data decryption activities is also recommended.