Description
Use of hard-coded cryptographic key vulnerability in Johnson Controls Airwall allows : Cryptanalytic Attack.

This issue affects Airwall: before 4.1.
Published: 2026-08-14
Score: 7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Johnson Controls Airwall contains a hard‑coded cryptographic key that can be extracted and used in a cryptanalytic attack. The key compromise can allow an adversary to decrypt protection mechanisms, potentially exposing sensitive data or undermining the integrity of secure communications. The vulnerability is identified as CWE-321.

Affected Systems

The affected system is Johnson Controls Airwall, with all versions prior to 4.1 impacted. No other vendors or products are listed as affected.

Risk and Exploitability

The CVSS score of 7 indicates a high‑impact vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is not explicitly stated in the advisory; the likely vector is inferred to be either local or remote, depending on how Airwall’s cryptographic functions are exposed in the operator’s environment. Given the moderate‑to‑high severity and potential for data compromise, the risk of exploitation remains significant.

Generated by OpenCVE AI on August 14, 2026 at 20:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Airwall to version 4.1 or later to remove the hard‑coded key
  • Reconfigure Airwall to utilize dynamically generated, unique keys for all cryptographic operations
  • Implement regular key management and rotation policies to prevent future hard‑coded key usage

Generated by OpenCVE AI on August 14, 2026 at 20:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 14 Aug 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 14 Aug 2026 19:45:00 +0000

Type Values Removed Values Added
Description Use of hard-coded cryptographic key vulnerability in Johnson Controls Airwall allows : Cryptanalytic Attack. This issue affects Airwall: before 4.1.
Title Airwall - Hardcoded Secrets
First Time appeared Johnson Controls
Johnson Controls airwall
Weaknesses CWE-321
CPEs cpe:2.3:a:johnson_controls:airwall:*:*:*:*:*:*:*:*
Vendors & Products Johnson Controls
Johnson Controls airwall
References
Metrics cvssV4_0

{'score': 7, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Johnson Controls Airwall
cve-icon MITRE

Status: PUBLISHED

Assigner: jci

Published:

Updated: 2026-08-14T19:50:22.102Z

Reserved: 2026-07-20T19:51:19.089Z

Link: CVE-2026-64887

cve-icon Vulnrichment

Updated: 2026-08-14T19:50:17.523Z

cve-icon NVD

Status : Received

Published: 2026-08-14T20:16:55.603

Modified: 2026-08-14T20:16:55.603

Link: CVE-2026-64887

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-14T20:45:03Z

Weaknesses
  • CWE-321

    Use of Hard-coded Cryptographic Key