Description
Cwe-327 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Johnson Controls TL280 allows Cryptanalytic Attack.

This issue affects TL280: before 5.63.
Published: 2026-08-14
Score: 2.9 Low
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability involves the use of a broken or risky cryptographic algorithm, potentially enabling cryptanalytic attacks against data processed by Johnson Controls TL280 devices. An attacker might exploit weaknesses in the algorithm to recover sensitive information, compromising confidentiality and potentially integrity if the algorithm is used for authentication or signing.

Affected Systems

The affected product is Johnson Controls TL280, specifically firmware versions earlier than 5.63. No other vendors or product versions are listed in the advisory.

Risk and Exploitability

The CVSS score of 2.9 indicates a low overall impact, and the EPSS score is not available. Because the advisory does not describe an explicit attack vector, it is inferred that an attacker would need to have some form of access to the device’s cryptographic operations or the data it handles. The vulnerability is not listed in CISA’s KEV catalog, suggesting limited current exploitation activity.

Generated by OpenCVE AI on August 14, 2026 at 20:38 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the device firmware to version 5.63 or higher.
  • If a firmware upgrade is not available, disable the use of the weak algorithm or enforce stronger encryption if configuration permits.
  • Verify that the device no longer uses the vulnerable algorithm by reviewing configuration and logs, and monitor for abnormal traffic or cryptanalysis attempts.

Generated by OpenCVE AI on August 14, 2026 at 20:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-327
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 14 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Cwe-327 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Johnson Controls TL280 allows Cryptanalytic Attack. This issue affects TL280: before 5.63.
Title TL280
First Time appeared Johnson Controls
Johnson Controls tl280
CPEs cpe:2.3:a:johnson_controls:tl280:*:*:*:*:*:*:*:*
Vendors & Products Johnson Controls
Johnson Controls tl280
References
Metrics cvssV4_0

{'score': 2.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Johnson Controls Tl280
cve-icon MITRE

Status: PUBLISHED

Assigner: jci

Published:

Updated: 2026-08-14T19:51:07.757Z

Reserved: 2026-02-24T11:29:18.530Z

Link: CVE-2026-27871

cve-icon Vulnrichment

Updated: 2026-08-14T19:51:02.731Z

cve-icon NVD

Status : Received

Published: 2026-08-14T20:16:52.670

Modified: 2026-08-14T20:16:52.670

Link: CVE-2026-27871

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T20:45:03Z

Weaknesses
  • CWE-327

    Use of a Broken or Risky Cryptographic Algorithm