Johnson Controls Inc. Airwall

MonitorCVSS 6.8ICS-CERT ICSA-26-225-03Aug 13, 2026
Johnson Controls
Attack path
Attack VectorLocal
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

Johnson Controls Airwall versions 4.0.4 and earlier contain hardcoded cryptographic keys that can be exploited to decrypt sensitive data and bypass authentication controls. An attacker with local access to an Airwall device could read arbitrary files and access protected system resources. The vulnerability stems from embedding cryptographic keys directly in source code or configuration files rather than using secure key management systems.

What this means
What could happen
An attacker with local access to an Airwall device could decrypt sensitive data and bypass authentication controls, potentially reading arbitrary files or accessing protected system resources.
Who's at risk
This affects organizations running Johnson Controls Airwall access control or network segmentation devices (version 4.0.4 and earlier). Critical for sites in manufacturing, utilities, healthcare, and other industrial environments that rely on Airwall for perimeter defense or network isolation.
How it could be exploited
An attacker with local access to the Airwall device can exploit hardcoded cryptographic keys embedded in the firmware or configuration files to decrypt sensitive data and bypass authentication mechanisms, then read arbitrary files or access protected resources on the system.
Prerequisites
  • Local access to the Airwall device (physical or via compromised local account)
  • Access to firmware or configuration files containing hardcoded cryptographic keys
Hardcoded cryptographic keys in firmwareLocal authentication bypass possibleSensitive data exposureAffects access control systems
Exploitability
Unlikely to be exploited — EPSS score 0.3%
Affected products (1)
ProductAffected VersionsFix Status
Airwall≤ 4.0.4No fix yet
Remediation & Mitigation
0/6
Do now
0/2
HARDENINGRemove any hardcoded cryptographic keys from Airwall firmware and configuration files
WORKAROUNDRestrict local access to Airwall devices through physical security controls and strong local authentication
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXUpdate all Airwall devices to firmware version 4.1.0 or later
Long-term hardening
0/3
HARDENINGImplement a cryptographic key management system (KMS) or hardware security module (HSM) to store all keys securely instead of embedding them in code or configuration
HARDENINGEstablish a key rotation policy to replace cryptographic keys on a regular schedule
HARDENINGUse unique cryptographic keys for each Airwall device, installation, or deployment to limit the impact of a single compromised key
API: /api/v1/advisories/f9bd479d-6863-4161-a592-a9e56eab1cd0

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.