Executive brief
Johnson Controls TL280 is a building automation and control system used to manage HVAC and facility infrastructure. The system uses weak or outdated cryptographic algorithms that could potentially be broken through cryptanalytic attacks, undermining the confidentiality and integrity of communications and data within the building control network.
Technical details
This vulnerability is classified as CWE-327 (Use of a Broken or Risky Cryptographic Algorithm), indicating the TL280 employs cryptographic algorithms that are either cryptographically broken or are considered risky and inappropriate for modern security requirements. The vulnerability allows cryptanalytic attacks against the affected system. No active exploitation in the wild has been reported. The vulnerability affects TL280 versions prior to 5.63. A patch or update is available to remediate this issue.
Affected products
- Johnson Controls TL280 before 5.63
Timeline
- 2026-08-14: disclosed