THREAT INTELLIGENCE CYBERTTAKv3.0.3.0
LIVE FEED ACTIVE
← Back to Intel Feed
Secure route: /intel/ai-johnson-controls-airwall-vulnerabilities-hard-coded-keys-and-arbitrary-file-read-2da8c039
highCVE-2026-648872026-08-13Vector: appsec

Johnson Controls Airwall Vulnerabilities: Hard-coded Keys and Arbitrary File Read

Johnson Controls has identified two security vulnerabilities in its Airwall product that could allow attackers to access sensitive data or read files they should not be able to see. Users are strongly advised to update their Airwall software to version 4.1.0 or later.

Decision Context

English Brief

Johnson Controls has identified two security vulnerabilities in its Airwall product that could allow attackers to access sensitive data or read files they should not be able to see. Users are strongly advised to update their Airwall software to version 4.1.0 or later.

الموجز العربي

ثغرات في منتج Johnson Controls Airwall: مفاتيح مشفرة ثابتة وقراءة ملفات غير مصرح بها

حددت شركة Johnson Controls ثغرتين أمنيتين في منتج Airwall الخاص بها، مما قد يسمح للمهاجمين بالوصول إلى بيانات حساسة أو قراءة ملفات لا ينبغي لهم الوصول إليها. يُنصح المستخدمون بشدة بتحديث برنامج Airwall إلى الإصدار 4.1.0 أو أحدث.

Affected Products
    Priority sectors
    Critical ManufacturingCommercial FacilitiesGovernment Services and FacilitiesTransportation SystemsEnergy
    Immediate Actions
    1. 1Update all Johnson Controls Airwall instances to version 4.1.0 or later.
    2. 2Audit and rotate all cryptographic keys used by the Airwall application.
    3. 3Restrict access to the Airwall management interfaces via firewalls/VPNs.