← Back to home
ICSA-23-206-04  ·  Published 2023-07-25  ·  View on CISA ICS-CERT ↗

Johnson Controls IQ Wifi 6

CVSS 8.3 HIGH

Risk Summary

Successful exploitation of this vulnerability could allow an unauthorized user to gain account access by conducting a brute force authentication attack.

CVEs (1)

Remediations

  • Johnson Controls recommends apply the following mitigations to reduce the risk:
  • Upgrade IQ Wifi 6 firmware to version 2.0.2. (Contact Johnson Controls for assistance)
  • The firmware update will be pushed to all available devices in the field.
  • The firmware update can also be manually loaded by applying the patch tag "iqwifi2.0.2" on the device after navigating to its firmware update page.
  • For additional information, see Johnson Controls Product Security Advisory JCI-PSA-2023-06 v1.

Affected Vendors

Johnson Controls Inc.

Affected Products (1)

Johnson Controls Inc. · IQ Wifi 6 Firmware < 2.0.2

Affected Sectors

Critical Manufacturing

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more