Impact
The vulnerability involves the use of a broken or risky cryptographic algorithm, potentially enabling cryptanalytic attacks against data processed by Johnson Controls TL280 devices. An attacker might exploit weaknesses in the algorithm to recover sensitive information, compromising confidentiality and potentially integrity if the algorithm is used for authentication or signing.
Affected Systems
The affected product is Johnson Controls TL280, specifically firmware versions earlier than 5.63. No other vendors or product versions are listed in the advisory.
Risk and Exploitability
The CVSS score of 2.9 indicates a low overall impact, and the EPSS score is not available. Because the advisory does not describe an explicit attack vector, it is inferred that an attacker would need to have some form of access to the device’s cryptographic operations or the data it handles. The vulnerability is not listed in CISA’s KEV catalog, suggesting limited current exploitation activity.
OpenCVE Enrichment