As cited
Copy frozen at (site build).
vulnerabilities
Johnson Controls Inc. TL280
Johnson Controls Inc. TL280 devices versions below 5.63 contain hardcoded credentials that use broken cryptographic algorithms, allowing attackers to access sensitive information with a CVSS score of 4.1. The vendor released firmware update 5.63 to address the vulnerability and recommends network segmentation, access restrictions, credential rotation, and regular firmware integrity checks.
Why it matters: Organizations managing TL280 devices in critical infrastructure (manufacturing, energy, transportation, government facilities) worldwide must patch to version 5.63 immediately and restrict network access to prevent unauthorized authentication using embedded credentials.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Johnson Controls Inc. TL280
Johnson Controls Inc. TL280 devices versions below 5.63 contain hardcoded credentials that use broken cryptographic algorithms, allowing attackers to access sensitive information with a CVSS score of 4.1. The vendor released firmware update 5.63 to address the vulnerability and recommends network segmentation, access restrictions, credential rotation, and regular firmware integrity checks.
Why it matters: Organizations managing TL280 devices in critical infrastructure (manufacturing, energy, transportation, government facilities) worldwide must patch to version 5.63 immediately and restrict network access to prevent unauthorized authentication using embedded credentials.
- Source published
- First seen by Cybersecurity Tracker