news.mlab.sh
Back to the feed
vulnerability

Johnson Controls Inc. TL280

Critical
Summary

A critical vulnerability (CWE-327) exists in Johnson Controls Inc.'s TL280 firmware, allowing attackers to access sensitive information on the device. The vulnerability stems from hardcoded credentials embedded directly in the firmware. Affected versions include TL280 < 5.63, and the device is deployed worldwide. Johnson Controls recommends applying firmware update 5.63 and implementing network segmentation and restricted access to mitigate the risk.

A critical vulnerability, identified as CWE-327 Use of a Broken or Risky Cryptographic Algorithm, has been discovered in Johnson Controls Inc.’s TL280 device. This vulnerability is due to hardcoded credentials – usernames, passwords, or other authentication information – being directly embedded within the firmware files. The TL280 device, manufactured by Johnson Controls Inc., is deployed globally, including in Critical Infrastructure Sectors such as Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, and Energy.

Johnson Controls recommends applying firmware update 5.63 to address this issue. To further mitigate the risk, the vendor suggests restricting network access to affected cameras to trusted management VLANs only, preventing direct exposure to the internet or untrusted network segments. Monitoring device access logs for any anomalous authentication activity is also advised.

Additionally, organizations should rotate any shared or downstream credentials derived from or associated with the hard-coded values. Implementing network segmentation and placing ICS/SCADA devices and systems behind firewalls, isolating them from the business network, is a crucial step. When remote access is required, secure methods like Virtual Private Networks (VPNs) should be used, recognizing that VPNs themselves may have vulnerabilities and should be kept up to date. Finally, regular firmware integrity checks should be conducted to detect unauthorized modifications.

Read the full article at CISA Advisories