Cyber Resilience
← All news

Johnson Controls Inc. TL280

Our takeCISA published ICSA-26-218-02: Johnson Controls TL280 <5.63 uses broken cryptography that can expose sensitive device data. Update to 5.63 or later.
Sources (1)
What this means for you — Security leader:Update Johnson Controls TL280 devices to firmware 5.63 or later. The vulnerability is a use of a broken or risky cryptographic algorithm that can expose sensitive information.
What this means for you — Lean IT orgs:If you have a Johnson Controls TL280 security panel or communicator, update its firmware to version 5.63 or newer as soon as you can.
What this means for you — MSP:Audit client environments for Johnson Controls TL280 devices running firmware below 5.63 and schedule immediate updates.
What this means for you — Researcher:Johnson Controls TL280 <5.63 carries a CVSS 4.1 flaw (use of a broken or risky cryptographic algorithm) that can leak sensitive device information. Fixed in 5.63.