CISA Flags Vulnerabilities in Johnson Controls Airwall Security Devices
CISA has issued an advisory regarding two vulnerabilities affecting Johnson Controls Inc. Airwall devices running version 4.0.4 and earlier. The flaws include the use of a hard-coded cryptographic key and an issue allowing external control of file names or paths, which together could let an attacker decrypt sensitive data, bypass authentication, read arbitrary files, or access protected system resources without authorization.
The affected product is used across multiple critical infrastructure sectors worldwide, including critical manufacturing, commercial facilities, government services, transportation, and energy. Johnson Controls, headquartered in Ireland, has products deployed globally, meaning organisations using Airwall for secure network segmentation should treat this advisory seriously, even though the vulnerabilities carry a moderate CVSS score of 6.8.
While Australian small businesses may not directly operate Airwall devices, many rely on managed service providers or larger partners who use industrial control and network security products like this. Understanding how vulnerabilities in third-party security tools can cascade through supply chains is an important part of overall cyber risk awareness.