Impact
Johnson Controls Airwall contains a hard‑coded cryptographic key that can be extracted and used in a cryptanalytic attack. The key compromise can allow an adversary to decrypt protection mechanisms, potentially exposing sensitive data or undermining the integrity of secure communications. The vulnerability is identified as CWE-321.
Affected Systems
The affected system is Johnson Controls Airwall, with all versions prior to 4.1 impacted. No other vendors or products are listed as affected.
Risk and Exploitability
The CVSS score of 7 indicates a high‑impact vulnerability. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is not explicitly stated in the advisory; the likely vector is inferred to be either local or remote, depending on how Airwall’s cryptographic functions are exposed in the operator’s environment. Given the moderate‑to‑high severity and potential for data compromise, the risk of exploitation remains significant.
OpenCVE Enrichment