Full Report
[Control Systems] Johnson Controls security advisory (AV26-837)
Analysis Summary
# Vulnerability: Multiple Flaws in Johnson Controls Building Automation and Networking Products
## CVE Details
- **CVE ID:** Specific CVE IDs are not listed in the summary advisory; refer to vendor documentation.
- **CVSS Score:** N/A (Refer to vendor advisory for individual scores)
- **CWE:** Varies by product (Commonly includes Authentication Bypass or Improper Input Validation in these product lines)
## Affected Systems
- **Products:**
- Airwall
- Metasys (Building Automation System)
- TL280 (Internet Alarm Communicator)
- **Versions:**
- Airwall: All versions prior to 4.1.0
- Metasys 12: All versions
- Metasys 13: All versions
- Metasys 14: All versions prior to v14.1.5
- Metasys 15: All versions prior to v15.0.1
- TL280: All versions prior to v5.62
- **Configurations:** Systems integrated into OT/ICS environments utilizing these management and communication modules.
## Vulnerability Description
While the specific technical flaw for each version is hosted on the Johnson Controls Trust Center, these advisories typically involve security weaknesses in the management interface or communication protocols of the building automation systems (Metasys) and secure networking components (Airwall). The vulnerabilities could potentially allow unauthorized access or disruption of control systems.
## Exploitation
- **Status:** Not specified as "exploited in the wild" in the primary advisory.
- **Complexity:** Typically Medium to High for ICS environments.
- **Attack Vector:** Primarily Network.
## Impact
- **Confidentiality:** Potential for unauthorized data access.
- **Integrity:** Potential for unauthorized modification of building control parameters.
- **Availability:** Risk of denial-of-service to critical building infrastructure.
## Remediation
### Patches
Johnson Controls recommends upgrading to the following versions or higher:
- **Airwall:** Upgrade to v4.1.0 or later.
- **Metasys 14:** Upgrade to v14.1.5.
- **Metasys 15:** Upgrade to v15.0.1.
- **TL280:** Upgrade to v5.62.
- *Note: Metasys 12 and 13 users should contact their representative for migration paths to supported versions.*
### Workarounds
- Isolate affected Building Automation Systems (BAS) from the public internet.
- Implement strict firewall rules to limit access to Metasys management ports to authorized IP addresses only.
- Ensure all default credentials have been changed.
## Detection
- Monitor for unusual login attempts or administrative changes within the Metasys management console.
- Audit network traffic for unauthorized connections to TL280 or Airwall management interfaces.
- Utilize ICS-aware IDS/IPS signatures for Johnson Controls protocols.
## References
- Johnson Controls - Product Security Advisories: hxxps[://]www[.]johnsoncontrols[.]com/trust-center/cybersecurity/security-advisories
- Canadian Centre for Cyber Security (AV26-837): hxxps[://]www[.]cyber[.]gc[.]ca/en/alerts-advisories/control-systems-johnson-controls-security-advisory-av26-837