Description
Use of hard-coded cryptographic key vulnerability in Johnson Controls ADVMS allows Read Sensitive Constants Within an Executable.

This issue affects ADVMS: before 3.10.
Published: 2026-10-07
Score: 8.5 High
EPSS: n/a
KEV: No
Impact: Data Exposure
Action: Immediate Patch
AI Analysis

Impact

The vulnerability arises from the use of a hard‑coded cryptographic key within the Johnson Controls ADVMS codebase, which allows an attacker to read sensitive constants contained in the executable. This flaw enables the discovery of cryptographic keys or other confidential data that the application relies upon to secure communications or stored information. The impact is primarily the exposure of confidential data rather than code execution or denial of service.

Affected Systems

Johnson Controls ADVMS versions earlier than 3.10 are affected. Systems running any of these releases could contain the hard‑coded key and thus the secret constants residing in the executable binary.

Risk and Exploitability

The CVSS score of 8.5 indicates a high severity. The EPSS is not available, making it difficult to quantify the likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack likely requires local or remote access to read the executable file; however, the vulnerability description does not explicitly state an exposed interface or network service, so the attack vector is inferred as a potential local compromise or exploitation of privileged file read operations.

Generated by OpenCVE AI on October 7, 2026 at 20:20 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Johnson Controls ADVMS to version 3.10 or later to eliminate the hard‑coded key
  • If an immediate upgrade is not possible, reconfigure the system to use a unique encryption key stored in a protected configuration file outside the executable
  • Restrict file system access to the ADVMS executable and any configuration files to prevent unauthorized reading of sensitive constants

Generated by OpenCVE AI on October 7, 2026 at 20:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 07 Oct 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 07 Oct 2026 20:45:00 +0000

Type Values Removed Values Added
Title Hard-Coded Cryptographic Key Exposed in Johnson Controls ADVMS

Wed, 07 Oct 2026 19:45:00 +0000

Type Values Removed Values Added
Description Use of hard-coded cryptographic key vulnerability in Johnson Controls ADVMS allows Read Sensitive Constants Within an Executable. This issue affects ADVMS: before 3.10.
Weaknesses CWE-321
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jci

Published:

Updated: 2026-10-07T20:37:35.137Z

Reserved: 2026-03-30T08:25:11.763Z

Link: CVE-2026-34499

cve-icon Vulnrichment

Updated: 2026-10-07T20:37:29.882Z

cve-icon NVD

Status : Received

Published: 2026-10-07T20:17:12.527

Modified: 2026-10-07T21:17:16.170

Link: CVE-2026-34499

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-07T20:30:13Z

Weaknesses
  • CWE-321

    Use of Hard-coded Cryptographic Key