External Control of File Name Vulnerability in Johnson Controls EasyIO FS32
CVE-2026-71453
5.6MEDIUM
What is CVE-2026-71453?
The EasyIO FS32 by Johnson Controls exhibits a vulnerability where external inputs can influence file names or paths, allowing potential attackers to conduct path traversal attacks. This could enable unauthorized access to sensitive files or directories, compromising the integrity and confidentiality of the system. Users of EasyIO FS32 are advised to update to version 3.0b63 or later to mitigate this risk effectively.
Affected Version(s)
EasyIO FS32 0 < 3.0b63
References
CVSS V4
Score:
5.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Adjacent Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Gabriele Gardois, Zachary Bushell and Lorenzo De Carli
