Impact
External control of a file name or path in Johnson Controls Airwall before version 4.1 permits attackers to read arbitrary files, a vulnerability classified as CWE-73. This enables unauthorized file access and the potential disclosure of sensitive configuration data or system files, compromising confidentiality and providing footholds for further exploits.
Affected Systems
Johnson Controls Airwall, all versions prior to 4.1, on any platform where the product is deployed, are affected.
Risk and Exploitability
The CVSS score of 7.0 indicates a moderate severity. EPSS is not available, and the vulnerability is not yet listed in CISA KEV, suggesting limited publicly known exploitation. The likely attack vector involves any source that can interact with the Airwall component, such as network or remote configuration interfaces, where an attacker can supply a crafted file name or path. Successful exploitation requires sufficient privileges to read the target file and basic input validation bypass; no additional authentication or privilege escalation is needed beyond normal access to Airwall.
OpenCVE Enrichment