Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-3611

Опубликовано: 12 мар. 2026
Источник: nvd
CVSS3: 10
EPSS Низкий

Описание

The Honeywell IQ4x building management controller, exposes its full web-based HMI without authentication in its factory-default configuration. With no user module configured, security is disabled by design and the system operates under a System Guest (level 100) context, granting read/write privileges to any party able to reach the HTTP interface. Authentication controls are only enforced after a web user is created via U.htm, which dynamically enables the user module. Because this function is accessible prior to authentication, a remote user can create a new account with administrative read/write permissions enabling the user module and imposing authentication under attacker-controlled credentials. This action can effectively lock legitimate operators out of local and web-based configuration and administration.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:honeywell:iq4e_firmware:*:*:*:*:*:*:*:*
Версия до 3.30 (исключая)
cpe:2.3:h:honeywell:iq4e:-:*:*:*:*:*:*:*
Конфигурация 2

Одновременно

cpe:2.3:o:honeywell:iq412_firmware:*:*:*:*:*:*:*:*
Версия до 3.30 (исключая)
cpe:2.3:h:honeywell:iq412:-:*:*:*:*:*:*:*
Конфигурация 3

Одновременно

cpe:2.3:o:honeywell:iq422_firmware:*:*:*:*:*:*:*:*
Версия до 3.30 (исключая)
cpe:2.3:h:honeywell:iq422:-:*:*:*:*:*:*:*
Конфигурация 4

Одновременно

cpe:2.3:o:honeywell:iq4nc_firmware:*:*:*:*:*:*:*:*
Версия до 3.30 (исключая)
cpe:2.3:h:honeywell:iq4nc:-:*:*:*:*:*:*:*
Конфигурация 5

Одновременно

cpe:2.3:o:honeywell:iq41x_firmware:*:*:*:*:*:*:*:*
Версия до 3.30 (исключая)
cpe:2.3:h:honeywell:iq41x:-:*:*:*:*:*:*:*

EPSS

Процентиль: 92%
0.05585
Низкий

10 Critical

CVSS3

Дефекты

CWE-306

Связанные уязвимости

CVSS3: 10
github
5 месяцев назад

The Honeywell IQ4x building management controller, exposes its full web-based HMI without authentication in its factory-default configuration. With no user module configured, security is disabled by design and the system operates under a System Guest (level 100) context, granting read/write privileges to any party able to reach the HTTP interface. Authentication controls are only enforced after a web user is created via U.htm, which dynamically enables the user module. Because this function is accessible prior to authentication, a remote user can create a new account with administrative read/write permissions enabling the user module and imposing authentication under attacker-controlled credentials. This action can effectively lock legitimate operators out of local and web-based configuration and administration.

CVSS3: 10
fstec
4 месяца назад

Уязвимость микропрограммного обеспечения программируемых логических контроллеров Honeywell IQ4, связанная с отсутствием аутентификации для критичной функции, позволяющая нарушителю получить полный доступ к устройству

EPSS

Процентиль: 92%
0.05585
Низкий

10 Critical

CVSS3

Дефекты

CWE-306