Impact
The vulnerability arises from the use of a hard‑coded cryptographic key within the Johnson Controls ADVMS codebase, which allows an attacker to read sensitive constants contained in the executable. This flaw enables the discovery of cryptographic keys or other confidential data that the application relies upon to secure communications or stored information. The impact is primarily the exposure of confidential data rather than code execution or denial of service.
Affected Systems
Johnson Controls ADVMS versions earlier than 3.10 are affected. Systems running any of these releases could contain the hard‑coded key and thus the secret constants residing in the executable binary.
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity. The EPSS is not available, making it difficult to quantify the likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the attack likely requires local or remote access to read the executable file; however, the vulnerability description does not explicitly state an exposed interface or network service, so the attack vector is inferred as a potential local compromise or exploitation of privileged file read operations.
OpenCVE Enrichment