An unauthorized user could gain account access to IQ Wifi 6 versions prior to 2.0.2 by conducting a brute force authentication attack.
Solution:
The product does not implement sufficient measures to prevent multiple failed authentication attempts within a short time frame.
Link | Tags |
---|---|
https://www.johnsoncontrols.com/cyber-solutions/security-advisories | vendor advisory |
https://www.cisa.gov/news-events/ics-advisories/icsa-23-206-04 | third party advisory us government resource |