looks like there was a USB vuln between 4.0.0 and 4.0.1 that would be referenced to. given USB as the threat vector, an air gapped setup would not be affected. I don't believe he is complicit based on a number of things but this needed some clarification