Impact
The vulnerability is an Improper Privilege Management flaw in Johnson Controls Easy IO FG, allowing attackers to brute force credentials. An attacker who obtains valid credentials or guesses them can gain unauthorized privileged access, compromising the confidentiality, integrity, and availability of the system. The primary impact is the potential for an attacker to elevate access rights and perform unauthorized actions within the device. The weakness corresponds to CWE-269.
Affected Systems
Johnson Controls Easy IO FG, versions prior to 2.0b52 are affected by this flaw.
Risk and Exploitability
The CVSS score of 5.6 indicates a moderate risk level. No EPSS score is available, so the historical exploitation probability is unknown, but the flaw has not been reported in the CISA KEV catalog. The exploit likely requires network access to the device or internal network access that would enable brute force attempts against privileged accounts. The attack vector is inferred as Local/Network depending on network segmentation, but the description explicitly states it permits brute force.
OpenCVE Enrichment