ICSA-23-206-04
·
Published 2023-07-25
·
View on CISA ICS-CERT ↗
Johnson Controls IQ Wifi 6
CVSS 8.3
HIGH
Risk Summary
Successful exploitation of this vulnerability could allow an unauthorized user to gain account access by conducting a brute force authentication attack.
CVEs (1)
Remediations
- Johnson Controls recommends apply the following mitigations to reduce the risk:
- Upgrade IQ Wifi 6 firmware to version 2.0.2. (Contact Johnson Controls for assistance)
- The firmware update will be pushed to all available devices in the field.
- The firmware update can also be manually loaded by applying the patch tag "iqwifi2.0.2" on the device after navigating to its firmware update page.
- For additional information, see Johnson Controls Product Security Advisory JCI-PSA-2023-06 v1.
Affected Vendors
Johnson Controls Inc.
Affected Products (1)
Johnson Controls Inc.
·
IQ Wifi 6 Firmware
< 2.0.2
Affected Sectors
Critical Manufacturing
Get alerted to advisories like this
OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.
Start free trial Learn more