CVE-2026-64887
7.0Johnson Controls · Airwall
A hard-coded cryptographic key vulnerability in Johnson Controls Airwall enables local cryptanalytic attacks, potentially compromising data confidentiality.
Executive summary
The Johnson Controls Airwall software contains a hard-coded cryptographic key vulnerability that poses a high risk to data confidentiality for local users.
Vulnerability
This vulnerability involves the use of hard-coded cryptographic keys, which allows an unauthenticated, local attacker to perform cryptanalytic operations. The flaw resides in the software's key management implementation, facilitating unauthorized access to encrypted data.
Business impact
The exploitation of this vulnerability could lead to the exposure of sensitive information encrypted by the Airwall software. With a CVSS score of 7.0, this issue is classified as high severity, indicating a significant potential for data breach and loss of trust in the security of the infrastructure. Organizations relying on Airwall for secure communications may face severe regulatory and operational consequences if the underlying cryptographic protections are bypassed.
Remediation
Immediate Action: Update the Johnson Controls Airwall software to version 4.1 or later to remove the hard-coded cryptographic keys.
Proactive Monitoring: Monitor local system access logs and audit trails for unauthorized attempts to interact with cryptographic services or unconventional authentication patterns.
Compensating Controls: Implement strict physical and logical access controls to limit the number of users capable of local interaction with the affected systems, thereby reducing the attack surface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high CVSS score and the nature of the vulnerability, organizations must prioritize upgrading to version 4.1 immediately. Relying on perimeter defenses alone is insufficient, as this vulnerability requires local access to execute. Apply the vendor-supplied update across all affected instances to restore cryptographic integrity.