<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Airwall - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/airwall/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 13 Aug 2026 16:52:07 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/airwall/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Johnson Controls Airwall Hard-coded Credentials and Path Traversal Vulnerabilities</title><link>https://feed.craftedsignal.io/briefs/2026-08-johnson-controls-airwall/</link><pubDate>Thu, 13 Aug 2026 16:52:07 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-johnson-controls-airwall/</guid><description>Johnson Controls Airwall versions 4.0.4 and earlier are affected by CVE-2026-64887 and CVE-2026-34492, allowing attackers to potentially decrypt sensitive data or perform arbitrary file reads.</description><content:encoded><![CDATA[<p>Johnson Controls has disclosed two vulnerabilities affecting Airwall products up to and including version 4.0.4. The first, CVE-2026-64887, involves the use of hard-coded cryptographic keys within the application, which are consistent across all installations. This allows an attacker who obtains the key through code analysis or binary inspection to decrypt sensitive application data, configuration files, and database content. The second issue, CVE-2026-34492, is an arbitrary file read vulnerability caused by improper validation of user-supplied input in file system operations. Attackers can leverage path traversal sequences (e.g., ../ or encoded variations) to read sensitive files from the underlying server, including private keys and credential stores. These vulnerabilities pose a significant risk to critical infrastructure sectors, including manufacturing, energy, and transportation, as they could lead to full system compromise if exploited in tandem.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of these vulnerabilities allows an attacker to gain unauthorized access to sensitive system information. By extracting private keys and credentials, an attacker could escalate privileges or pivot into internal networks. Given the deployment of these devices in critical infrastructure sectors, the compromise of Airwall appliances could result in significant operational disruption and data exfiltration.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade all instances of Johnson Controls Airwall to version 4.1.0 or later immediately to patch both CVE-2026-64887 and CVE-2026-34492.</li>
<li>Audit existing deployments for unauthorized access to configuration files and sensitive key stores.</li>
<li>Implement network segmentation and strictly restrict management access to these devices, ensuring they are not exposed to the public internet.</li>
<li>Consult the Johnson Controls Product Security Advisory JCI-PSA-2026-25 and JCI-PSA-2026-18 for detailed hardening steps and remediation guidance.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>ics</category><category>cve-2026-64887</category><category>cve-2026-34492</category></item></channel></rss>