Executive brief
Johnson Controls Airwall is a network security appliance used to protect building automation and control systems. An attacker with access to the device could manipulate file paths to read, write, or delete files outside intended directories, potentially compromising system integrity or gaining unauthorized access to sensitive configurations.
Technical details
This vulnerability is classified as external control of file name or path (CWE-73 or similar), allowing an attacker to manipulate file path operations in Airwall. The vulnerability affects versions before 4.1. Although the reported severity is marked as "info," the vulnerability class (file manipulation through path traversal) could enable attackers to read sensitive files, overwrite system files, or escalate privileges depending on the application's execution context and file permissions. Attack vectors and specific preconditions (authentication requirement, network reachability) are not detailed in the advisory. Patches should be available in version 4.1 and later.
Affected products
- Johnson Controls Airwall before 4.1
Timeline
- 2026-08-14: disclosed